CVE-2011-2170: Input Validation
Published May 24, 2011
·Updated
Google Chrome OS before R12 0.12.433.38 Beta, when Guest mode is enabled, does not prevent changes on the about:flags page, which has unspecified impact and local attack vectors.
Affected Software
31 affected components
Google Chrome OS=0.11.257.39
Google Chrome OS=8.0.552.342
Google Chrome OS=0.11.257.14
Google Chrome OS=0.10.156.4
Google Chrome OS=0.10.142.3
Google Chrome OS=0.10.156.30
Google Chrome OS=0.10.146.1
Google Chrome OS=8.0.552.344
Google Chrome OS=0.10.156.18
Google Chrome OS=8.0.552.343
Google Chrome OS<=0.12.433.35
Google Chrome OS=0.11.257.91
Google Chrome OS=0.10.156.36
Google Chrome OS=0.10.156.54
Google Chrome OS=0.12.433.28
Google Chrome OS=0.11.257.18
Google Chrome OS=0.12.362.2
Google Chrome OS=0.11.257.32
Google Chrome OS=0.11.227.0
Google Chrome OS=0.12.397.0
Google Chrome OS=0.10.156.34
Google Chrome OS=0.9.126.0
Google Chrome OS=0.10.156.1
Google Chrome OS=0.10.156.50
Google Chrome OS=0.10.156.46
Google Chrome OS=0.11.257.44
Google Chrome OS=0.12.433.22
Google Chrome OS=0.11.257.3
Google Chrome OS=0.10.156.20
Google Chrome OS=0.12.433.14
Google Chrome OS=0.12.433.9
Event History
May 24, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2170?
CVE-2011-2170 has an unspecified impact that could lead to local attack vectors due to guest mode vulnerabilities.
2
How do I fix CVE-2011-2170?
To mitigate CVE-2011-2170, update your Google Chrome OS to a version that is R12 0.12.433.38 Beta or later.
3
What versions of Google Chrome OS are affected by CVE-2011-2170?
CVE-2011-2170 affects multiple versions of Google Chrome OS prior to R12 0.12.433.38.
4
What is the nature of the vulnerability in CVE-2011-2170?
The vulnerability in CVE-2011-2170 allows changes on the about:flags page in Guest mode.
5
Can CVE-2011-2170 affect system security?
Yes, CVE-2011-2170 can potentially compromise system security by allowing unauthorized changes.