CVE-2012-4454
10.10.2012, 18:55
openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.Enginsight
Vendor | Product | Version |
---|---|---|
opencryptoki_project | opencryptoki | 𝑥 ≤ 2.4 |
opencryptoki_project | opencryptoki | 2.2.3 |
opencryptoki_project | opencryptoki | 2.2.4 |
opencryptoki_project | opencryptoki | 2.2.4.1 |
opencryptoki_project | opencryptoki | 2.2.5 |
opencryptoki_project | opencryptoki | 2.2.6 |
opencryptoki_project | opencryptoki | 2.2.7 |
opencryptoki_project | opencryptoki | 2.2.8 |
opencryptoki_project | opencryptoki | 2.3.0 |
opencryptoki_project | opencryptoki | 2.3.1 |
opencryptoki_project | opencryptoki | 2.3.2 |
opencryptoki_project | opencryptoki | 2.3.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References