Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Debian: DSA-2435-1 Moderate Severity: Gnash Local Attack Vulnerability

debian
Calendar Grey March 20, 2012
Scroller Debian
Several vulnerabilities in Gnash Flash player necessitate urgent patches to mitigate exploitation threats and avert possible data breaches.
Several vulnerabilities have been identified in Gnash, the GNU Flash player

Summary

Several vulnerabilities have been identified in Gnash, the GNU Flash
player.

CVE-2012-1175

Tielei Wang from Georgia Tech Information Security Center discovered a
vulnerability in GNU Gnash which is caused due to an integer overflow
error and can be exploited to cause a heap-based buffer overflow by
tricking a user into opening a specially crafted SWF file.

CVE-2011-4328

Alexander Kurtz discovered an unsafe management of HTTP cookies. Cookie
files are stored under /tmp and have predictable names, vulnerability
that allows a local attacker to overwrite arbitrary files the users has
write permissions for, and are also world-readable which may cause
information leak.

CVE-2010-4337

Jakub Wilk discovered an unsafe management of temporary files during the
build process. Files are stored under /tmp and have predictable names,
vulnerability that allows a local attacker to overwrite arbitrary files
the users has write permissions for.

For the stable distribution (squeeze), this probl...

Read the Full Advisory

Package: gnash
CVE ID: CVE-2010-4337 CVE-2011-4328 CVE-2012-1175

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.