CVE-2012-4454 — Insecure Temporary File in Project Opencryptoki
Severity
2.9LOWNVD
EPSS
0.7%
top 28.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 10
Latest updateMay 17
Description
openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.
CVSS vector
AV:A/AC:M/C:N/I:P/A:NExploitability: 5.5 | Impact: 2.9
Affected Packages2 packages
🔴Vulnerability Details
3📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2012-4454 CVE-2012-4455 opencryptoki: insecure handling of files in the /tmp directory↗2011-08-15