CVE-2011-4328

plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows local users to obtain sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
gnugnash
𝑥
≤ 0.8.9
gnugnash
0.8.5
gnugnash
0.8.7
gnugnash
0.8.8
gnugnash
0.8.9:rc4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnash
saucy
Fixed 0.8.10-3ubuntu1
released
raring
Fixed 0.8.10-3ubuntu1
released
quantal
Fixed 0.8.10-3ubuntu1
released
precise
Fixed 0.8.10-3ubuntu1
released
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
hardy
ignored
Common Weakness Enumeration