First published: Mon Oct 01 2012(Updated: )
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gnome-shell | =3.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4427 is considered a moderate severity vulnerability that can lead to unauthorized installation of extensions.
To fix CVE-2012-4427, you should upgrade to a later version of GNOME Shell that is not affected by this vulnerability.
Users of GNOME Shell version 3.4.1 are primarily affected by CVE-2012-4427.
CVE-2012-4427 allows attackers to exploit a remote code execution vulnerability through crafted web pages.
CVE-2012-4427 is not categorized as a zero-day vulnerability since it was publicly disclosed in 2012.