CVE-2008-5749: Code Injection
DISPUTED Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5749?
CVE-2008-5749 is classified as a disputed vulnerability, which could potentially allow remote code execution under certain conditions.
How do I fix CVE-2008-5749?
To mitigate CVE-2008-5749, users should update Google Chrome to a version later than 1.0.154.36.
Which versions of Google Chrome are affected by CVE-2008-5749?
CVE-2008-5749 specifically affects Google Chrome version 1.0.154.36 on Windows XP SP3.
Can CVE-2008-5749 be exploited without user interaction?
CVE-2008-5749 requires user interaction to execute arbitrary commands via the --renderer-path option.
Is CVE-2008-5749 specific to any operating system?
Yes, CVE-2008-5749 is specifically reported on Windows XP SP3 with Google Chrome version 1.0.154.36.