CVE-2012-4427Code Injection in Gnome-shell

CWE-94Code Injection9 documents7 sources
Severity
6.8MEDIUMNVD
EPSS
1.0%
top 22.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateMay 17

Description

The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

Debiangnome/gnome-shell< 3.34.0-2+3

🔴Vulnerability Details

3
GHSA
GHSA-gxj3-vwm6-2f7w: The gnome-shell plugin 32022-05-17
OSV
CVE-2012-4427: The gnome-shell plugin 32012-10-01
CVEList
CVE-2012-4427: The gnome-shell plugin 32012-10-01

📋Vendor Advisories

1
Debian
CVE-2012-4427: gnome-shell - The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the downl...2012

🕵️Threat Intelligence

1
Tenable
Nessus 5.0.2 Available2012-10-10

💬Community

2
Bugzilla
CVE-2012-4427 gnome shell: browser integration plugin installs extensions without authorization2012-09-17
Bugzilla
CVE-2012-4427 gnome shell: browser integration plugin installs extensions without authorization [fedora-all]2012-09-17
CVE-2012-4427 — Code Injection in Gnome Gnome-shell | cvebase