Unrated severityNVD Advisory· Published Jun 16, 2012· Updated Apr 29, 2026
CVE-2011-4328
CVE-2011-4328
Description
plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows local users to obtain sensitive information.
Affected products
5Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/48325nvdVendor Advisory
- secunia.com/advisories/48466nvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- lists.opensuse.org/opensuse-updates/2012-03/msg00003.htmlnvd
- lists.opensuse.org/opensuse-updates/2012-03/msg00026.htmlnvd
- www.debian.org/security/2012/dsa-2435nvd
- www.openwall.com/lists/oss-security/2011/11/21/12nvd
- www.openwall.com/lists/oss-security/2011/11/21/7nvd
- www.osvdb.org/77243nvd
- www.securityfocus.com/bid/50747nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.