PT-2016-7544 · Objective Development · Little Snitch
Patrick Wardle
·
Published
2016-11-15
·
Updated
2020-11-09
·
CVE-2016-8661
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Little Snitch versions 3.0 through 3.6.1
Description
The issue is related to a buffer overflow that could be locally exploited, potentially leading to an escalation of privileges and unauthorized access to the operating system. This buffer overflow is due to insufficient checking of parameters to the
OSMalloc and copyin kernel API calls.Recommendations
For Little Snitch versions 3.0 through 3.6.1, consider restricting access to the
OSMalloc and copyin kernel API calls as a temporary mitigation measure until a patch is available.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Little Snitch