CVE-2011-4328

CWE-2645 documents4 sources
Severity
5.0MEDIUM
EPSS
0.4%
top 36.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16
Latest updateMay 17

Description

plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows local users to obtain sensitive information.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDgnu/gnash0.8.9+4

🔴Vulnerability Details

2
GHSA
GHSA-43gq-7wp4-9vh5: plugin/npapi/plugin2022-05-17
CVEList
CVE-2011-4328: plugin/npapi/plugin2012-06-16

💬Community

2
Bugzilla
CVE-2011-4328 gnash: Unsafe management of HTTP cookies [fedora-all]2011-11-21
Bugzilla
CVE-2011-4328 gnash: Unsafe management of HTTP cookies2011-11-21