Vulnerability Name: | CVE-2011-2486 (CCN-68321) | ||||||||||||||||||||||||||||||||
Assigned: | 2011-03-25 | ||||||||||||||||||||||||||||||||
Published: | 2011-03-25 | ||||||||||||||||||||||||||||||||
Updated: | 2013-09-01 | ||||||||||||||||||||||||||||||||
Summary: | nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.9 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2011-2486 Source: MISC Type: UNKNOWN http://lwn.net/Alerts/524725/ Source: CCN Type: nspluginwrapper Web site nspluginwrapper Source: CCN Type: RHSA-2012-1459 Low: nspluginwrapper security and bug fix update Source: REDHAT Type: UNKNOWN RHSA-2012:1459 Source: CCN Type: BID-48487 nspluginwrapper Private Browsing Flash Player Storage Local Information Disclosure Vulnerability Source: SECTRACK Type: Patch 1027757 Source: CONFIRM Type: UNKNOWN https://bugzilla.novell.com/show_bug.cgi?id=702034 Source: CCN Type: Red Hat Bugzilla Bug 715384 CVE-2011-2486 nspluginwrapper does not forward NPNVprivateModeBool variable Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=715384 Source: XF Type: UNKNOWN nspluginwrapper-player-info-disclosure(68321) Source: MISC Type: UNKNOWN https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |