First published: Mon Nov 21 2011(Updated: )
A security flaw was found in the way Shockwave Flash plug-in of the gnash, a GNU flash movie player, performed management of HTTP cookies (they were stored under /tmp directory with world-readable permissions). A local attacker could use this flaw to obtain sensitive information. References: [1] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=649384">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=649384</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Gnash | <=0.8.9 | |
GNU Gnash | =0.8.5 | |
GNU Gnash | =0.8.7 | |
GNU Gnash | =0.8.8 | |
GNU Gnash | =0.8.9-rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.