Untrusted search path vulnerability in Mozilla Network Security Services (NSS),...
Vulnerability Description
Untrusted search path vulnerability in Mozilla Network Security Services (NSS), as used in Google Chrome before 17 on Windows and Mac OS X, might allow local users to gain privileges via a Trojan horse pkcs11.txt file in a top-level directory. NOTE: the vendor's response was "Strange behavior, but we're not treating this as a security bug."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-3640
Credits & Attribution
No credits recorded in the NVD database.
References
- https://hermes.opensuse.org/messages/13155432
- https://hermes.opensuse.org/messages/13154861
- http://securityreason.com/securityalert/8483
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13414
- http://blog.acrossecurity.com/2011/10/google-chrome-pkcs11txt-file-planting.html
- http://code.google.com/p/chromium/issues/detail?id=97426
- https://bugzilla.mozilla.org/show_bug.cgi?id=641052
More from google
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.