CVE-ID |
CVE-2018-1000006
|
• Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings
|
Description |
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier,
1.6.15 and earlier has a vulnerability in the protocol handler,
specifically Electron apps running on Windows 10, 7 or 2008 that
register custom protocol handlers can be tricked in arbitrary command
execution if the user clicks on a specially crafted URL. This has been
fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.
|
References |
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
|
|
Assigning CNA |
Distributed Weakness Filing Project |
Date Entry Created |
20180119 |
Disclaimer: The entry creation date may reflect when
the CVE-ID was allocated or reserved, and does not
necessarily indicate when this vulnerability was
discovered, shared with the affected vendor, publicly
disclosed, or updated in CVE.
|
Phase (Legacy) |
Assigned (20180119) |
Votes (Legacy) |
|
Comments (Legacy) |
|
Proposed (Legacy) |
N/A |
This is an entry on the CVE
list, which standardizes names for security
problems. |
|
For More Information: cve@mitre.org
|