PT-2012-5410 · Opencryptoki+1 · Opencryptoki+1

Tomas Hoger

·

Published

2012-10-10

·

Updated

2023-02-13

·

CVE-2012-4454

CVSS v2.0

2.9

Low

VectorAV:A/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions openCryptoki versions prior to 2.4.1
Description The issue allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the .pkapi xpk or .pkcs11spinloc file in /tmp. This is possible when using spinlocks.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /tmp directory to minimize the risk of exploitation. Avoid using spinlocks until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2012-4454
SUSE-SU-2012_1705-1

Affected Products

Suse
Opencryptoki