PT-2012-5543 · Tunnelblick · Tunnelblick

Kurt Seifried

·

Published

2012-08-26

·

Updated

2012-08-27

·

CVE-2012-4676

CVSS v2.0

1.2

Low

VectorAV:L/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tunnelblick versions 3.3beta20 and earlier
Description The issue allows local users to delete arbitrary files by constructing a symlink or hard link. This is a result of a problem in the errorExitIfAttackViaString function.
Recommendations For versions 3.3beta20 and earlier, consider disabling the errorExitIfAttackViaString function as a temporary workaround until a patch is available. Restrict access to sensitive files to minimize the risk of exploitation.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4676

Affected Products

Tunnelblick