Access Control Vulnerabilities in Amazon Kindle Touch
CVE-2012-4248
Currently unrated
What is CVE-2012-4248?
The Amazon Kindle Touch prior to version 5.1.2 contains an access control vulnerability in the libkindleplugin.so NPAPI plugin interface. This flaw can potentially allow remote attackers to exploit several methods, including dev.log, lipc.set, lipc.get, and todo.scheduleItems, to perform unauthorized actions that could impact system integrity and data confidentiality.
References
Timeline
Vulnerability Reserved
Vulnerability published