spice-xpi: multiple vulnerabilities
| Package(s): | spice-xpi | CVE #(s): | CVE-2011-0012 CVE-2011-1179 | ||||||||||||
| Created: | April 8, 2011 | Updated: | April 15, 2011 | ||||||||||||
| Description: | From the Red Hat advisory:
An uninitialized pointer use flaw was found in the SPICE Firefox plug-in. If a user were tricked into visiting a malicious web page with Firefox while the SPICE plug-in was enabled, it could cause Firefox to crash or, possibly, execute arbitrary code with the privileges of the user running Firefox. (CVE-2011-1179) It was found that the SPICE Firefox plug-in used a predictable name for one of its log files. A local attacker could use this flaw to conduct a symbolic link attack, allowing them to overwrite arbitrary files accessible to the user running Firefox. (CVE-2011-0012) | ||||||||||||||
| Alerts: |
| ||||||||||||||
