[Forgot Password]
Login  Register Subscribe

23631

 
 

115084

 
 

97147

 
 

909

 
 

78730

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2012-3483

Date: (C)2012-08-26   (M)2015-12-16 


Race condition in the runScript function in Tunnelblick 3.3beta20 and earlier allows local users to gain privileges by replacing a script file.

CVSS Score: 6.2Access Vector: LOCAL
Exploit Score: 1.9Access Complexity: HIGH
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
http://archives.neohapsis.com/archives/fulldisclosure/2012-08/0122.html
http://www.openwall.com/lists/oss-security/2012/08/14/1
http://code.google.com/p/tunnelblick/issues/detail?id=212
http://git.zx2c4.com/Pwnnel-Blicker/tree/pwnnel-blicker.c

CWE    1
CWE-362

© 2013 SecPod Technologies