nspluginwrapper NPNVprivateModeBool Variable Processing Flaw Lets Remote Users Deny Service
|
SecurityTracker Alert ID: 1027757 |
SecurityTracker URL: http://securitytracker.com/id/1027757
|
CVE Reference:
CVE-2011-2486
(Links to External Site)
|
Date: Nov 14 2012
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in nspluginwrapper. A remote user can cause denial of service conditions.
nspluginwrapper does not forward the NPNVprivateModeBool variable. Certain applications using the wrapper may crash and require a restart.
|
Impact:
A remote user may be able to cause the target user's application to crash.
|
Solution:
The vendor has issued a source code fix, available at:
https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98
|
Vendor URL: nspluginwrapper.org/ (Links to External Site)
|
Cause:
State error
|
Underlying OS: Linux (Any), UNIX (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|