6.2
CVSSv2

CVE-2012-4455

Published: 10/10/2012 Updated: 13/02/2023
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

opencryptoki project opencryptoki 2.4.1

Vendor Advisories

Debian Bug report logs - #689417 opencryptoki: CVE-2012-4454 CVE-2012-4455 Package: opencryptoki; Maintainer for opencryptoki is Paulo Vital <pvital@gmailcom>; Source for opencryptoki is src:opencryptoki (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 2 Oct 2012 12:42:03 UTC Sever ...