Description
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-10950 | The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0. |
References
| Link | Providers |
|---|---|
| https://www.facebook.com/security/advisories/cve-2021-24030 |
|
History
No history.
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2024-08-03T19:21:17.165Z
Reserved: 2021-01-13T00:00:00.000Z
Link: CVE-2021-24030
No data.
Status : Modified
Published: 2021-03-10T16:15:16.813
Modified: 2024-11-21T05:52:14.697
Link: CVE-2021-24030
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD