PT-2012-5543 · Tunnelblick · Tunnelblick

Kurt Seifried

·

Publicado

2012-08-26

·

Atualizado

2012-08-27

·

CVE-2012-4676

CVSS v2.0

1.2

Baixa

VetorAV:L/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tunnelblick versions 3.3beta20 and earlier
Description The issue allows local users to delete arbitrary files by constructing a symlink or hard link. This is a result of a problem in the errorExitIfAttackViaString function.
Recommendations For versions 3.3beta20 and earlier, consider disabling the errorExitIfAttackViaString function as a temporary workaround until a patch is available. Restrict access to sensitive files to minimize the risk of exploitation.

Exploit

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4676

Produtos afetados

Tunnelblick