CVE-2012-3485
26.08.2012, 19:55
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call.Enginsight
Vendor | Product | Version |
---|---|---|
tunnelblick | 𝑥 ≤ 3.3beta20 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References