Candidate: CVE-2011-4328 PublicDate: 2012-06-16 00:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4328 Description: plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows local users to obtain sensitive information. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=649384 Priority: medium Discovered-by: Alexander Kurtz Assigned-to: CVSS: Patches_gnash: upstream_gnash: released (0.8.10-1) hardy_gnash: ignored (reached end-of-life) lucid_gnash: ignored (reached end-of-life) maverick_gnash: ignored (reached end-of-life) natty_gnash: ignored (reached end-of-life) oneiric_gnash: ignored (reached end-of-life) precise_gnash: released (0.8.10-3ubuntu1) quantal_gnash: released (0.8.10-3ubuntu1) raring_gnash: released (0.8.10-3ubuntu1) saucy_gnash: released (0.8.10-3ubuntu1) devel_gnash: released (0.8.10-3ubuntu1)