Access Control Vulnerabilities in Amazon Kindle Touch
CVE-2012-4248

Currently unrated

Key Information:

Vendor

Amazon

Vendor
CVE Published:
12 August 2012

What is CVE-2012-4248?

The Amazon Kindle Touch prior to version 5.1.2 contains an access control vulnerability in the libkindleplugin.so NPAPI plugin interface. This flaw can potentially allow remote attackers to exploit several methods, including dev.log, lipc.set, lipc.get, and todo.scheduleItems, to perform unauthorized actions that could impact system integrity and data confidentiality.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.