PT-2019-12863 · London Trust Media+1 · Private Internet Access (Pia) Vpn Client+1
Rich Mirch
·
Publicado
2019-07-11
·
Atualizado
2021-09-08
·
CVE-2019-12573
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
London Trust Media Private Internet Access (PIA) VPN Client version v82
Description
A local attacker could exploit this issue to overwrite arbitrary files, potentially leading to a denial of service condition and data loss. The
openvpn launcher binary, which is setuid root, has a --log option that accepts a path as an argument. This --log parameter is not properly sanitized, allowing a local unprivileged user to overwrite files owned by any user, including root.Recommendations
For London Trust Media Private Internet Access (PIA) VPN Client version v82, consider disabling the
openvpn launcher binary or restricting its use until a patch is available to prevent local users from overwriting arbitrary files.Exploit
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openvpn
Private Internet Access (Pia) Vpn Client