Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 373971 (CVE-2011-2486) - <www-plugins/nspluginwrapper-1.4.4: Does not honor private browsing (CVE-2011-2486)
Summary: <www-plugins/nspluginwrapper-1.4.4: Does not honor private browsing (CVE-2011...
Status: RESOLVED FIXED
Alias: CVE-2011-2486
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/davidben/nspluginw...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-07-04 00:02 UTC by Tim Sammut (RETIRED)
Modified: 2011-10-08 21:18 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2011-07-04 00:02:55 UTC
Fix at $URL. From the Red Hat bug at https://bugzilla.redhat.com/show_bug.cgi?id=715384:

nspluginwrapper forwards variable values requested via NPN_GetValue from
firefox to the plugins it wraps around. One of the variables,
NPNVprivateModeBool, is used to tell the plugin if firefox is in private
browsing mode. The flash plugin (when it is wrapped by nspluginwrapper)
queries the browser via nsplugin wrapper and changes its behaviour
accordingly. However, the nspluginwrapper versions in RHEL-5 and RHEL-6 do
not implement this variable and simply return an error:

*** NSPlugin Viewer *** WARNING: unhandled variable 18 (<unknown variable>) in
NPN_GetValue()

where the enum 18 is NPNVprivateModeBool. As a result, the flash player may
continue to run as if the browser is not in private mode.

The fix for this issue can be found here:
https://github.com/davidben/nspluginwrapper/commit/7e4ab8e1189846041f955e6c83f72bc1624e7a98
Comment 1 Patrick McLean gentoo-dev 2011-07-04 15:38:42 UTC
I have committed www-plugins/nspluginwrapper-1.4.4 which includes the fix.

We should be able to stabilize it as it has fairly minimal changes since the previous version.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-07-04 16:08:54 UTC
(In reply to comment #1)
> I have committed www-plugins/nspluginwrapper-1.4.4 which includes the fix.
> 
> We should be able to stabilize it as it has fairly minimal changes since the
> previous version.

Great, thank you.

Arches, please test and mark stable:
=www-plugins/nspluginwrapper-1.4.4
Target keywords : "amd64"
Comment 3 Agostino Sarubbo gentoo-dev 2011-07-04 19:07:06 UTC
works for me
Comment 4 Markos Chandras (RETIRED) gentoo-dev 2011-07-05 07:55:31 UTC
seems good to me as well. amd64 done. Thanks Agostino
Comment 5 Tim Sammut (RETIRED) gentoo-dev 2011-07-05 13:09:09 UTC
Thanks, folks. GLSA Vote: No.
Comment 6 Pierre-Yves Rofes (RETIRED) gentoo-dev 2011-10-08 21:18:25 UTC
no too, and closing.