CVE-2012-4455Link Following in Project Opencryptoki

Severity
6.2MEDIUMNVD
EPSS
0.0%
top 93.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateMay 17

Description

openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.

CVSS vector

AV:L/AC:H/C:C/I:C/A:CExploitability: 1.9 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-45q7-7mrv-f7jr: openCryptoki 22022-05-17
OSV
CVE-2012-4455: openCryptoki 22012-10-10
CVEList
CVE-2012-4455: openCryptoki 22012-10-10

📋Vendor Advisories

2
Red Hat
opencryptoki: insecure handling of files in the /tmp directory2012-09-07
Debian
CVE-2012-4455: opencryptoki - openCryptoki 2.4.1 allows local users to create or set world-writable permission...2012

💬Community

1
Bugzilla
CVE-2012-4454 CVE-2012-4455 opencryptoki: insecure handling of files in the /tmp directory2011-08-15
CVE-2012-4455 — Link Following in Project Opencryptoki | cvebase