Skip to navigation

Security Advisory Low: nspluginwrapper security and bug fix update

Advisory: RHSA-2012:1459-1
Type: Security Advisory
Severity: Low
Issued on: 2012-11-13
Last updated on: 2012-11-13
Affected Products: Red Hat Enterprise Linux Desktop (v. 6)
Red Hat Enterprise Linux HPC Node (v. 6)
Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Server EUS (v. 6.3.z)
Red Hat Enterprise Linux Workstation (v. 6)
CVEs (cve.mitre.org): CVE-2011-2486

Details

Updated nspluginwrapper packages that fix one security issue and one bug
are now available for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having low
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

nspluginwrapper is a utility which allows 32-bit plug-ins to run in a
64-bit browser environment (a common example is Adobe's browser plug-in for
presenting proprietary Flash files embedded in web pages). It includes the
plug-in viewer and a tool for managing plug-in installations and updates.

It was not possible for plug-ins wrapped by nspluginwrapper to discover
whether the browser was running in Private Browsing mode. This flaw could
lead to plug-ins wrapped by nspluginwrapper using normal mode while they
were expected to run in Private Browsing mode. (CVE-2011-2486)

This update also fixes the following bug:

* When using the Adobe Reader web browser plug-in provided by the
acroread-plugin package on a 64-bit system, opening Portable Document
Format (PDF) files in Firefox could cause the plug-in to crash and a black
window to be displayed where the PDF should be. Firefox had to be restarted
to resolve the issue. This update implements a workaround in
nspluginwrapper to automatically handle the plug-in crash, so that users
no longer have to keep restarting Firefox. (BZ#869554)

All users of nspluginwrapper are advised to upgrade to these updated
packages, which upgrade nspluginwrapper to upstream version 1.4.4, and
correct these issues. After installing the update, Firefox must be
restarted for the changes to take effect.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258

Updated packages

Red Hat Enterprise Linux Desktop (v. 6)

SRPMS:
nspluginwrapper-1.4.4-1.el6_3.src.rpm     MD5: 8ec7b628b68509a577423bffc7d826fe
SHA-256: 0409e6b99c5545b3e04f4628d67055eab0980bd1d3d36915b069ce9af88252c4
 
IA-32:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
 
x86_64:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-1.4.4-1.el6_3.x86_64.rpm     MD5: e98b97ca7418551c4d00576ea0d13c56
SHA-256: 9a6010185323f4a75f55790ece05cc7a77e79edfdd477973b383e556ba89bcea
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
nspluginwrapper-debuginfo-1.4.4-1.el6_3.x86_64.rpm     MD5: 4a943cbd7ae552c99eeca9dcde18d9b6
SHA-256: 21d218e147c127d6f532f11f7a992c66acf68ac88506369f4204d4264952c1bb
 
Red Hat Enterprise Linux HPC Node (v. 6)

SRPMS:
nspluginwrapper-1.4.4-1.el6_3.src.rpm     MD5: 8ec7b628b68509a577423bffc7d826fe
SHA-256: 0409e6b99c5545b3e04f4628d67055eab0980bd1d3d36915b069ce9af88252c4
 
x86_64:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-1.4.4-1.el6_3.x86_64.rpm     MD5: e98b97ca7418551c4d00576ea0d13c56
SHA-256: 9a6010185323f4a75f55790ece05cc7a77e79edfdd477973b383e556ba89bcea
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
nspluginwrapper-debuginfo-1.4.4-1.el6_3.x86_64.rpm     MD5: 4a943cbd7ae552c99eeca9dcde18d9b6
SHA-256: 21d218e147c127d6f532f11f7a992c66acf68ac88506369f4204d4264952c1bb
 
Red Hat Enterprise Linux Server (v. 6)

SRPMS:
nspluginwrapper-1.4.4-1.el6_3.src.rpm     MD5: 8ec7b628b68509a577423bffc7d826fe
SHA-256: 0409e6b99c5545b3e04f4628d67055eab0980bd1d3d36915b069ce9af88252c4
 
IA-32:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
 
PPC:
nspluginwrapper-1.4.4-1.el6_3.ppc.rpm     MD5: 5a5a36ca06fcf4fb64ee14b80cf5cfd1
SHA-256: ed958bc065936bbe04629ce3a5c49bfe1d07b0fe3804891ebd52c1d2ddf63c9d
nspluginwrapper-debuginfo-1.4.4-1.el6_3.ppc.rpm     MD5: 01e95f996313360f4afa8e237999aae7
SHA-256: ca09f22032729de6a5676c61d5d8b5f749a45178d5edbb5539e4b5f2df7fe5ac
 
x86_64:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-1.4.4-1.el6_3.x86_64.rpm     MD5: e98b97ca7418551c4d00576ea0d13c56
SHA-256: 9a6010185323f4a75f55790ece05cc7a77e79edfdd477973b383e556ba89bcea
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
nspluginwrapper-debuginfo-1.4.4-1.el6_3.x86_64.rpm     MD5: 4a943cbd7ae552c99eeca9dcde18d9b6
SHA-256: 21d218e147c127d6f532f11f7a992c66acf68ac88506369f4204d4264952c1bb
 
Red Hat Enterprise Linux Server EUS (v. 6.3.z)

SRPMS:
nspluginwrapper-1.4.4-1.el6_3.src.rpm     MD5: 8ec7b628b68509a577423bffc7d826fe
SHA-256: 0409e6b99c5545b3e04f4628d67055eab0980bd1d3d36915b069ce9af88252c4
 
IA-32:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
 
PPC:
nspluginwrapper-1.4.4-1.el6_3.ppc.rpm     MD5: 5a5a36ca06fcf4fb64ee14b80cf5cfd1
SHA-256: ed958bc065936bbe04629ce3a5c49bfe1d07b0fe3804891ebd52c1d2ddf63c9d
nspluginwrapper-debuginfo-1.4.4-1.el6_3.ppc.rpm     MD5: 01e95f996313360f4afa8e237999aae7
SHA-256: ca09f22032729de6a5676c61d5d8b5f749a45178d5edbb5539e4b5f2df7fe5ac
 
x86_64:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-1.4.4-1.el6_3.x86_64.rpm     MD5: e98b97ca7418551c4d00576ea0d13c56
SHA-256: 9a6010185323f4a75f55790ece05cc7a77e79edfdd477973b383e556ba89bcea
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
nspluginwrapper-debuginfo-1.4.4-1.el6_3.x86_64.rpm     MD5: 4a943cbd7ae552c99eeca9dcde18d9b6
SHA-256: 21d218e147c127d6f532f11f7a992c66acf68ac88506369f4204d4264952c1bb
 
Red Hat Enterprise Linux Workstation (v. 6)

SRPMS:
nspluginwrapper-1.4.4-1.el6_3.src.rpm     MD5: 8ec7b628b68509a577423bffc7d826fe
SHA-256: 0409e6b99c5545b3e04f4628d67055eab0980bd1d3d36915b069ce9af88252c4
 
IA-32:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
 
x86_64:
nspluginwrapper-1.4.4-1.el6_3.i686.rpm     MD5: 29b57e15128e7bf7a5fc07220b15211e
SHA-256: 5bc77c323b39a5b4806be28917d47bc1d27673827684f77e8b4cb49bedfacdda
nspluginwrapper-1.4.4-1.el6_3.x86_64.rpm     MD5: e98b97ca7418551c4d00576ea0d13c56
SHA-256: 9a6010185323f4a75f55790ece05cc7a77e79edfdd477973b383e556ba89bcea
nspluginwrapper-debuginfo-1.4.4-1.el6_3.i686.rpm     MD5: 7c2e63c766c144470fee1b0765694f98
SHA-256: 401ee9134c43a4abe47e3d7263ab57b5e62e22b0034ef5dbb14dc58d1d70e286
nspluginwrapper-debuginfo-1.4.4-1.el6_3.x86_64.rpm     MD5: 4a943cbd7ae552c99eeca9dcde18d9b6
SHA-256: 21d218e147c127d6f532f11f7a992c66acf68ac88506369f4204d4264952c1bb
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

715384 - CVE-2011-2486 nspluginwrapper: NPNVprivateModeBool variable not forwarded


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/