CVE-2011-2169: High severity chrome os vulnerability
Published May 24, 2011
·Updated
Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing commands in it.
Affected Software
31 affected components
Google Chrome OS=0.11.257.39
Google Chrome OS=8.0.552.342
Google Chrome OS=0.11.257.14
Google Chrome OS=0.10.156.4
Google Chrome OS=0.10.142.3
Google Chrome OS=0.10.156.30
Google Chrome OS=0.10.146.1
Google Chrome OS=8.0.552.344
Google Chrome OS=0.10.156.18
Google Chrome OS=8.0.552.343
Google Chrome OS<=0.12.433.35
Google Chrome OS=0.11.257.91
Google Chrome OS=0.10.156.36
Google Chrome OS=0.10.156.54
Google Chrome OS=0.12.433.28
Google Chrome OS=0.11.257.18
Google Chrome OS=0.12.362.2
Google Chrome OS=0.11.257.32
Google Chrome OS=0.11.227.0
Google Chrome OS=0.12.397.0
Google Chrome OS=0.10.156.34
Google Chrome OS=0.9.126.0
Google Chrome OS=0.10.156.1
Google Chrome OS=0.10.156.50
Google Chrome OS=0.10.156.46
Google Chrome OS=0.11.257.44
Google Chrome OS=0.12.433.22
Google Chrome OS=0.11.257.3
Google Chrome OS=0.10.156.20
Google Chrome OS=0.12.433.14
Google Chrome OS=0.12.433.9
Event History
May 24, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2169?
CVE-2011-2169 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2011-2169?
To fix CVE-2011-2169, users should update Google Chrome OS to the latest version that addresses the vulnerability.
3
Who is affected by CVE-2011-2169?
CVE-2011-2169 affects multiple versions of Google Chrome OS including versions prior to R12 0.12.433.38 Beta.
4
What type of attack can exploit CVE-2011-2169?
CVE-2011-2169 can be exploited by local users to gain elevated privileges on the affected system.
5
When was CVE-2011-2169 disclosed?
CVE-2011-2169 was disclosed in May 2011.