|
|
| |
|
| |
spice-xpi: multiple vulnerabilities
| Package(s): | spice-xpi |
CVE #(s): | CVE-2011-0012
CVE-2011-1179
|
| Created: | April 8, 2011 |
Updated: | April 15, 2011 |
| Description: |
From the Red Hat advisory:
An uninitialized pointer use flaw was found in the SPICE Firefox plug-in.
If a user were tricked into visiting a malicious web page with Firefox
while the SPICE plug-in was enabled, it could cause Firefox to crash or,
possibly, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2011-1179)
It was found that the SPICE Firefox plug-in used a predictable name for one
of its log files. A local attacker could use this flaw to conduct a
symbolic link attack, allowing them to overwrite arbitrary files accessible
to the user running Firefox. (CVE-2011-0012)
|
| Alerts: |
|
( Log in to post comments)
|
|
|