VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-3918
sleipnir: Fenrir Sleipnir 2.9.6 and earlier does not prevent ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-3918

Original

Fenrir Sleipnir 2.9.6 and earlier does not prevent interaction between web script and the clipboard, which allows remote attackers to read or modify the clipboard contents via a crafted web site.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-12-10
Source Information Category:
Advisory, Alert
Last Updated:
2010-12-13




Affected Product Tags
cpe:/a:fenrir-inc:sleipnir:2.5.10
cpe:/a:fenrir-inc:sleipnir:2.5.11
cpe:/a:fenrir-inc:sleipnir:2.5.12
cpe:/a:fenrir-inc:sleipnir:2.5.14
cpe:/a:fenrir-inc:sleipnir:2.7.2
cpe:/a:fenrir-inc:sleipnir:2.8.0
cpe:/a:fenrir-inc:sleipnir:2.8.1
cpe:/a:fenrir-inc:sleipnir:2.8.2
cpe:/a:fenrir-inc:sleipnir:2.8.3
cpe:/a:fenrir-inc:sleipnir:2.9.1
cpe:/a:fenrir-inc:sleipnir:2.9.2
cpe:/a:fenrir-inc:sleipnir:2.9.3
cpe:/a:fenrir-inc:sleipnir:2.9.4
cpe:/a:fenrir-inc:sleipnir:2.9.5
cpe:/a:fenrir-inc:sleipnir:2.9.6 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

Alternatives




References
CONFIRM http://www.fenrir.co.jp/blog/2010/11/post_47.html




CONFIRM http://fenrir-inc.blogspot.com/2010/11/vulnerability-regarding-allow-paste.html




JVN JVN#64764004




JVNDB JVNDB-2010-000057




OSVDB 69604




SECUNIA 42427




Vulnerability Type Permissions, Privileges, and Access Control (CWE-264)





Copyright © 2010 JPCERT/CC All Rights Reserved.