PT-2012-4768 · Unknown · Crypto-Utils
Vincent Danen
·
Published
2012-10-10
·
Updated
2017-08-29
·
CVE-2012-3504
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
crypto-utils version 2.4.1-34
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on the "list" file in the current working directory, specifically through the
nssconfigFound function in genkey.pl in crypto-utils.Recommendations
For crypto-utils version 2.4.1-34, consider restricting access to the
genkey.pl script until a patch is available, and avoid using the nssconfigFound function to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crypto-Utils