Back to search
CVE-2011-4328
Published: Jun 16, 2012
Modified: Aug 7, 2024
PUBLISHED
Description
plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows local users to obtain sensitive information.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20111121 Re: CVE Request (minor) -- gnash -- Unsafe management of HTTP cookies
mailing-list
x_refsource_MLIST
openSUSE-SU-2012:0330
vendor-advisory
x_refsource_SUSE
[oss-security] 20111121 CVE Request (minor) -- gnash -- Unsafe management of HTTP cookies
mailing-list
x_refsource_MLIST
48325
third-party-advisory
x_refsource_SECUNIA
50747
vdb-entry
x_refsource_BID
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=649384
x_refsource_MISC
openSUSE-SU-2012:0369
vendor-advisory
x_refsource_SUSE
DSA-2435
vendor-advisory
x_refsource_DEBIAN
77243
vdb-entry
x_refsource_OSVDB
https://bugzilla.redhat.com/show_bug.cgi?id=755518
x_refsource_MISC
48466
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now