5
CVSSv2

CVE-2011-4328

Published: 16/06/2012 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

plugin/npapi/plugin.cpp in Gnash prior to 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows local users to obtain sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gnash 0.8.7

gnu gnash 0.8.9

gnu gnash

gnu gnash 0.8.5

gnu gnash 0.8.8

Vendor Advisories

Several vulnerabilities have been identified in Gnash, the GNU Flash player CVE-2012-1175 Tielei Wang from Georgia Tech Information Security Center discovered a vulnerability in GNU Gnash which is caused due to an integer overflow error and can be exploited to cause a heap-based buffer overflow by tricking a user into opening a specially ...
Debian Bug report logs - #649384 gnash creates world-readable cookies under /tmp with predictable filenames Package: gnash; Maintainer for gnash is Debian Flash Team <pkg-flash-devel@listsaliothdebianorg>; Source for gnash is src:gnash (PTS, buildd, popcon) Reported by: Alexander Kurtz <kurtzalex@googlemailcom> ...
Debian Bug report logs - #605419 CVE-2010-4337 gnash: configure creates temp files insecurely Package: src:gnash; Maintainer for src:gnash is Debian Flash Team <pkg-flash-devel@listsaliothdebianorg>; Reported by: Jakub Wilk <jwilk@debianorg> Date: Mon, 29 Nov 2010 20:09:01 UTC Severity: normal Tags: security, squ ...
Debian Bug report logs - #664023 [CVE-2012-1175] gnash integer overflow Package: gnash; Maintainer for gnash is Debian Flash Team <pkg-flash-devel@listsaliothdebianorg>; Source for gnash is src:gnash (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 14 Mar 2012 22:27:16 UTC Severity ...