CVE Vulnerabilities

CVE-2011-2486

Published: Nov 19, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.

Affected Software

NameVendorStart VersionEnd Version
NspluginwrapperNspluginwrapper1.4.2 (including)1.4.2 (including)
Red Hat Enterprise Linux 6RedHatnspluginwrapper-0:1.4.4-1.el6_3*
NspluginwrapperUbuntuhardy*
NspluginwrapperUbuntulucid*
NspluginwrapperUbuntumaverick*
NspluginwrapperUbuntunatty*

References