cbcvebase.
CVE-2012-4455
published 2012-10-10

CVE-2012-4455: openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2)…

PriorityP417medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.36%
28.2th percentile
openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianopencryptoki< opencryptoki 3.4.1+dfsg-1 (bookworm)opencryptoki 3.4.1+dfsg-1 (bookworm)
opencryptoki_projectopencryptoki
opencryptoki_projectopencryptoki>= 0 < 3.4.1+dfsg-13.4.1+dfsg-1
opencryptoki_projectopencryptoki>= 0 < 3.4.1+dfsg-13.4.1+dfsg-1
opencryptoki_projectopencryptoki>= 0 < 3.4.1+dfsg-13.4.1+dfsg-1
opencryptoki_projectopencryptoki>= 0 < 3.4.1+dfsg-13.4.1+dfsg-1

CVSS provenance

nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2LOW
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.