nspluginwrapper Private Browsing Flash Player Storage Local Information Disclosure Vulnerability
BID:48487
Info
nspluginwrapper Private Browsing Flash Player Storage Local Information Disclosure Vulnerability
| Bugtraq ID: | 48487 |
| Class: | Design Error |
| CVE: |
CVE-2011-2486 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 28 2011 12:00AM |
| Updated: | Nov 14 2012 06:00AM |
| Credit: | David Benjamin |
| Vulnerable: |
nspluginwrapper nspluginwrapper 1.4.0 CentOS CentOS 6 |
| Not Vulnerable: |
nspluginwrapper nspluginwrapper 1.4.2 |
Discussion
nspluginwrapper Private Browsing Flash Player Storage Local Information Disclosure Vulnerability
nspluginwrapper is prone to a local information-disclosure vulnerability.
A local attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
nspluginwrapper is prone to a local information-disclosure vulnerability.
A local attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
Exploit / POC
nspluginwrapper Private Browsing Flash Player Storage Local Information Disclosure Vulnerability
A local attacker can use readily available tools to exploit this issue.
A local attacker can use readily available tools to exploit this issue.
Solution / Fix
nspluginwrapper Private Browsing Flash Player Storage Local Information Disclosure Vulnerability
Solution:
Vendor fixes are available. Please see the referenced advisory for details.
Solution:
Vendor fixes are available. Please see the referenced advisory for details.
References
nspluginwrapper Private Browsing Flash Player Storage Local Information Disclosure Vulnerability
References:
References:
- (CVE-2011-2486) CVE-2011-2486 nspluginwrapper does not forward NPNVprivateModeBo (Red Hat)
- nspluginwrapper Homepage (nspluginwrapper)
- Support all the new variables added (David Benjamin)