CVE-2012-4427: Code Injection
Published Oct 1, 2012
·Updated
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
Affected Software
1 affected component
Gnome gnome-shell=3.4.1
Event History
Oct 1, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4427?
CVE-2012-4427 is considered a moderate severity vulnerability that can lead to unauthorized installation of extensions.
2
How do I fix CVE-2012-4427?
To fix CVE-2012-4427, you should upgrade to a later version of GNOME Shell that is not affected by this vulnerability.
3
Who is affected by CVE-2012-4427?
Users of GNOME Shell version 3.4.1 are primarily affected by CVE-2012-4427.
4
What type of attack is related to CVE-2012-4427?
CVE-2012-4427 allows attackers to exploit a remote code execution vulnerability through crafted web pages.
5
Is CVE-2012-4427 a zero-day vulnerability?
CVE-2012-4427 is not categorized as a zero-day vulnerability since it was publicly disclosed in 2012.