2.9
CVSSv2

CVE-2012-4454

Published: 10/10/2012 Updated: 13/02/2023
CVSS v2 Base Score: 2.9 | Impact Score: 2.9 | Exploitability Score: 5.5
VMScore: 258
Vector: AV:A/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

openCryptoki prior to 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.

Vulnerable Product Search on Vulmon Subscribe to Product

opencryptoki project opencryptoki 2.3.3

opencryptoki project opencryptoki 2.2.7

opencryptoki project opencryptoki 2.2.4

opencryptoki project opencryptoki 2.2.3

opencryptoki project opencryptoki 2.2.8

opencryptoki project opencryptoki 2.2.5

opencryptoki project opencryptoki 2.3.1

opencryptoki project opencryptoki

opencryptoki project opencryptoki 2.2.4.1

opencryptoki project opencryptoki 2.3.2

opencryptoki project opencryptoki 2.3.0

opencryptoki project opencryptoki 2.2.6

Vendor Advisories

Debian Bug report logs - #689417 opencryptoki: CVE-2012-4454 CVE-2012-4455 Package: opencryptoki; Maintainer for opencryptoki is Paulo Vital <pvital@gmailcom>; Source for opencryptoki is src:opencryptoki (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 2 Oct 2012 12:42:03 UTC Sever ...