CVE-2012-4427
published 2012-10-01CVE-2012-4427: The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.29%
67.2th percentile
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnome-shell | < gnome-shell 3.34.0-2 (bookworm) | gnome-shell 3.34.0-2 (bookworm) |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | >= 0 < 3.34.0-2 | 3.34.0-2 |
| gnome | gnome-shell | >= 0 < 3.34.0-2 | 3.34.0-2 |
| gnome | gnome-shell | >= 0 < 3.34.0-2 | 3.34.0-2 |
| gnome | gnome-shell | >= 0 < 3.34.0-2 | 3.34.0-2 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gxj3-vwm6-2f7w: The gnome-shell plugin 3
ghsa_unreviewed·2022-05-17
CVE-2012-4427 [MEDIUM] CWE-94 GHSA-gxj3-vwm6-2f7w: The gnome-shell plugin 3
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
OSV
CVE-2012-4427: The gnome-shell plugin 3
osv·2012-10-01·CVSS 6.8
CVE-2012-4427 [MEDIUM] CVE-2012-4427: The gnome-shell plugin 3
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
Debian
CVE-2012-4427: gnome-shell - The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the downl...
vendor_debian·2012·CVSS 6.8
CVE-2012-4427 [MEDIUM] CVE-2012-4427: gnome-shell - The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the downl...
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
Scope: local
bookworm: resolved (fixed in 3.34.0-2)
bullseye: resolved (fixed in 3.34.0-2)
forky: resolved (fixed in 3.34.0-2)
sid: resolved (fixed in 3.34.0-2)
trixie: resolved (fixed in 3.34.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4427 gnome shell: browser integration plugin installs extensions without authorization
bugzilla·2012-09-17·CVSS 6.8
CVE-2012-4427 [MEDIUM] CVE-2012-4427 gnome shell: browser integration plugin installs extensions without authorization
CVE-2012-4427 gnome shell: browser integration plugin installs extensions without authorization
Tavis Ormandy discovered that the browser extension installed as part of Gnome Shell (libgnome-shell-browser-plugin.so) would install Gnome Shell extensions without authorization from the user running the browser. While the Gnome Shell extension installer does not install these extensions directly, it does pass them to Gnome Shell via D-BUS, which then in turn installs the extension from extensions.gnome.org. If a malicious user were to upload a malicious extensions to extensions.gnome.org and coerce a user into visiting a site where the extension installer would request that application's installation, the extension would be installed without the victim's knowledge.
Discussion:
The initial r
Bugzilla
CVE-2012-4427 gnome shell: browser integration plugin installs extensions without authorization [fedora-all]
bugzilla·2012-09-17·CVSS 6.8
CVE-2012-4427 [MEDIUM] CVE-2012-4427 gnome shell: browser integration plugin installs extensions without authorization [fedora-all]
CVE-2012-4427 gnome shell: browser integration plugin installs extensions without authorization [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraprojec
Tenable
Nessus 5.0.2 Available
blogs_tenable·2012-10-10·CVSS 5.3
[MEDIUM] Nessus 5.0.2 Available
Blog /
Subscribe
# Nessus 5.0.2 Available
Ron Gula
October 10, 2012
0 Min Read
Nessus 5.0.2 has been released and is available at http://www.nessus.org/download/. This update is largely a bugfix release, however a new build for Solaris 10 is now available.
The major issues addressed in 5.0.2 include enhanced support for UTF8 encoding problems in reports and the detection of network congestion errors during scans more conservatively. For a full list of addressed issues, please review the 5.0.2 availability announcement at the Nessus Discussion Forums.
## Related articles
May 13, 2025
## CVE-2025-4427, CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Remote Code Execution
Remote code execution vulnerability in a popular mobile device management solution from Ivanti has been exp
http://www.openwall.com/lists/oss-security/2012/09/08/1http://www.openwall.com/lists/oss-security/2012/09/13/19http://www.openwall.com/lists/oss-security/2012/09/13/26http://www.openwall.com/lists/oss-security/2012/09/18/3http://www.securityfocus.com/bid/55556https://bugzilla.gnome.org/show_bug.cgi?id=684215https://bugzilla.novell.com/show_bug.cgi?id=779473http://www.openwall.com/lists/oss-security/2012/09/08/1http://www.openwall.com/lists/oss-security/2012/09/13/19http://www.openwall.com/lists/oss-security/2012/09/13/26http://www.openwall.com/lists/oss-security/2012/09/18/3http://www.securityfocus.com/bid/55556https://bugzilla.gnome.org/show_bug.cgi?id=684215https://bugzilla.novell.com/show_bug.cgi?id=779473
2012-10-01
Published