CVE-2011-2486
Summary
| CVE | CVE-2011-2486 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-11-19 12:10:48 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nspluginwrapper | Nspluginwrapper | 1.4.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Support all the new variables added · davidben/nspluginwrapper@7e4ab8e · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| nspluginwrapper NPNVprivateModeBool Variable Processing Flaw Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Patch |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.novell.com | |
| Scientific Linux alert SL-nspl-20121113 (nspluginwrapper) [LWN.net] | af854a3a-2127-422b-91ae-364da2661108 | lwn.net | |
| Bug 715384 – CVE-2011-2486 nspluginwrapper does not forward NPNVprivateModeBool variable | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.