PT-2012-1558 · Mozilla+3 · Nspluginwrapper+4
Josh Bressers
·
Published
2012-11-13
·
Updated
2024-06-15
·
CVE-2011-2486
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
nspluginwrapper versions prior to 1.4.4
Description
The issue prevents Firefox plugins from determining if they should run in Private Browsing mode, allowing remote attackers to bypass intended access restrictions. This could be demonstrated using Flash, where the
NPNVprivateModeBool variable settings are not properly provided.Recommendations
For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to plugins that rely on Private Browsing mode until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Firefox
Flash
Red Hat
Nspluginwrapper