PT-2012-1558 · Mozilla+3 · Nspluginwrapper+4

Josh Bressers

·

Published

2012-11-13

·

Updated

2024-06-15

·

CVE-2011-2486

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions nspluginwrapper versions prior to 1.4.4
Description The issue prevents Firefox plugins from determining if they should run in Private Browsing mode, allowing remote attackers to bypass intended access restrictions. This could be demonstrated using Flash, where the NPNVprivateModeBool variable settings are not properly provided.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to plugins that rely on Private Browsing mode until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_1459
CVE-2011-2486
OPENSUSE-SU-2024:10270-1
RHSA-2012:1459
RHSA-2012_1459

Affected Products

Centos
Firefox
Flash
Red Hat
Nspluginwrapper