Google Chrome 'chromeHTML://' Command Line Parameter Injection Vulnerability
BID:32997
Info
Google Chrome 'chromeHTML://' Command Line Parameter Injection Vulnerability
| Bugtraq ID: | 32997 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5749 CVE-2008-5750 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 23 2008 12:00AM |
| Updated: | May 12 2015 07:48PM |
| Credit: | Nine:Situations:Group::strawdog |
| Vulnerable: |
Google Chrome 1.0.154.46 Google Chrome 1.0.154.36 |
| Not Vulnerable: | |
Discussion
Google Chrome 'chromeHTML://' Command Line Parameter Injection Vulnerability
Google Chrome is prone to a vulnerability that lets attackers inject command-line parameters through protocol handlers. This issue occurs because the application fails to adequately sanitize user-supplied input.
Exploiting this issue would permit remote attackers to influence command options that can be called through the vulnerable protocol handler and to execute commands and arbitrary code with the privileges of a user running the application.
Google Chrome 1.0.154.36 is vulnerable; other versions may also be affected.
Update (January 30, 2009): This issue occurs when the argument '--no-sandbox' is included in the URI passed to Google Chrome.
Google Chrome is prone to a vulnerability that lets attackers inject command-line parameters through protocol handlers. This issue occurs because the application fails to adequately sanitize user-supplied input.
Exploiting this issue would permit remote attackers to influence command options that can be called through the vulnerable protocol handler and to execute commands and arbitrary code with the privileges of a user running the application.
Google Chrome 1.0.154.36 is vulnerable; other versions may also be affected.
Update (January 30, 2009): This issue occurs when the argument '--no-sandbox' is included in the URI passed to Google Chrome.
Exploit / POC
Google Chrome 'chromeHTML://' Command Line Parameter Injection Vulnerability
The following examples are available:
The following examples are available:
Solution / Fix
Google Chrome 'chromeHTML://' Command Line Parameter Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Google Chrome 'chromeHTML://' Command Line Parameter Injection Vulnerability
References:
References:
- Google Chrome Homepage (Google)
- Google Chrome Browser (ChromeHTML://) remote parameter injection POC ([email protected])
- Re: Google Chrome Browser (ChromeHTML://) remote parameter injection POC ([email protected])
- Re: Re: Google Chrome Browser (ChromeHTML://) remote parameter injection POC ([email protected])
- Re: Re: Google Chrome Browser (ChromeHTML://) remote parameter injection POC ([email protected])