CVE-2011-3055: Medium severity google chrome (trace event) vulnerability
Published Mar 22, 2012
·Updated
The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers to have an unspecified impact via a crafted extension.
Affected Software
2 affected components
Google Chrome<17.0.963.83
openSUSE openSUSE=12.1
Event History
Mar 22, 2012
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3055?
CVE-2011-3055 has a medium severity rating due to the potential for user-assisted attacks through malicious extensions.
2
How do I fix CVE-2011-3055?
To fix CVE-2011-3055, update Google Chrome to version 17.0.963.83 or later.
3
What versions of Google Chrome are affected by CVE-2011-3055?
CVE-2011-3055 affects versions of Google Chrome prior to 17.0.963.83.
4
Can CVE-2011-3055 be exploited without user interaction?
No, CVE-2011-3055 requires user interaction to install the crafted extension.
5
What impact can CVE-2011-3055 have on users?
CVE-2011-3055 can allow attackers to execute arbitrary code if a user installs a malicious extension.