CVE Vulnerabilities

CVE-2011-2486

Published: Nov 19, 2012 | Modified: Sep 01, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.

Affected Software

Name Vendor Start Version End Version
Nspluginwrapper Nspluginwrapper 1.4.2 (including) 1.4.2 (including)
Red Hat Enterprise Linux 6 RedHat nspluginwrapper-0:1.4.4-1.el6_3 *
Nspluginwrapper Ubuntu hardy *
Nspluginwrapper Ubuntu lucid *
Nspluginwrapper Ubuntu maverick *
Nspluginwrapper Ubuntu natty *

References