CVE-2012-0842: Infoleak
Published Nov 19, 2019
·Updated
surf: cookie jar has read access from other local user
Affected Software
5 affected componentsFixes available
Suckless Surf<0.5
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/surf
2.0+git20201107-22.1+git20221016-42.1+git20250419-1
Event History
Nov 19, 2019
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·12:56 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-0842?
CVE-2012-0842 is classified as a medium-severity vulnerability due to improper permission settings.
2
How do I fix CVE-2012-0842?
To fix CVE-2012-0842, update the surf package to versions 2.0+git20201107-2, 2.1+git20221016-4, or 2.1+git20221016-6.
3
What does CVE-2012-0842 impact?
CVE-2012-0842 impacts the surf web browser allowing unauthorized local read access to the cookie jar.
4
Is CVE-2012-0842 specific to any operating systems?
CVE-2012-0842 specifically affects Debian GNU/Linux versions 8.0, 9.0, and 10.0.
5
Who is affected by CVE-2012-0842?
Users of the surf web browser on Debian systems are primarily affected by CVE-2012-0842.