PT-2012-5276 · Amazon · Amazon Kindle Touch

Eureka

·

Published

2012-08-12

·

Updated

2012-08-13

·

CVE-2012-4248

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Amazon Kindle Touch versions prior to 5.1.2
Description The issue is related to improper access restriction to the libkindleplugin.so NPAPI plugin interface. This might allow remote attackers to have an unspecified impact via vectors involving the dev.log, lipc.set, lipc.get, or todo.scheduleItems method.
Recommendations For Amazon Kindle Touch versions prior to 5.1.2, update to version 5.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the libkindleplugin.so NPAPI plugin interface until a patch is available. Avoid using the dev.log, lipc.set, lipc.get, or todo.scheduleItems method in the affected plugin interface until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4248

Affected Products

Amazon Kindle Touch