PT-2012-5410 · Opencryptoki+1 · Opencryptoki+1

·

CVE-2012-4454

·

Publicado

2012-10-10

·

Atualizado

2023-02-13

CVSS v2.0

2.9

Baixa

VetorAV:A/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions openCryptoki versions prior to 2.4.1
Description The issue allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the .pkapi xpk or .pkcs11spinloc file in /tmp. This is possible when using spinlocks.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /tmp directory to minimize the risk of exploitation. Avoid using spinlocks until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4454
SUSE-SU-2012_1705-1

Produtos afetados

Suse
Opencryptoki