First published: Sat Feb 23 2013(Updated: )
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitrary code via a crafted file.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE | =12.1 | |
openSUSE | =12.2 | |
Google Chrome | <25.0.1364.97 | |
Linux Kernel | ||
Microsoft Windows | ||
Google Chrome | <25.0.1364.99 | |
macOS Yosemite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0889 has a moderate severity rating due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2013-0889, update Google Chrome to version 25.0.1364.98 or later.
CVE-2013-0889 affects Google Chrome versions earlier than 25.0.1364.97 for Windows and Linux and earlier than 25.0.1364.99 for Mac OS X.
Yes, openSUSE versions 12.1 and 12.2 are also affected by CVE-2013-0889 when Google Chrome is installed.
The risks associated with CVE-2013-0889 include the possibility of remote code execution through crafted files downloaded without proper user gesture enforcement.