CVE-2012-4454Insecure Temporary File in Project Opencryptoki

Severity
2.9LOWNVD
EPSS
0.7%
top 28.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateMay 17

Description

openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.

CVSS vector

AV:A/AC:M/C:N/I:P/A:NExploitability: 5.5 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-mvr7-mrp6-366f: openCryptoki before 22022-05-17
OSV
CVE-2012-4454: openCryptoki before 22012-10-10
CVEList
CVE-2012-4454: openCryptoki before 22012-10-10

📋Vendor Advisories

2
Red Hat
opencryptoki: insecure handling of files in the /tmp directory2012-09-07
Debian
CVE-2012-4454: opencryptoki - openCryptoki before 2.4.1, when using spinlocks, allows local users to create or...2012

💬Community

1
Bugzilla
CVE-2012-4454 CVE-2012-4455 opencryptoki: insecure handling of files in the /tmp directory2011-08-15
CVE-2012-4454 — Insecure Temporary File | cvebase