Local privilege escalation vulnerability in Tunnelblick by OpenVPN Technologies
CVE-2012-3483

Currently unrated

Key Information:

Vendor

Google

Vendor
CVE Published:
26 August 2012

What is CVE-2012-3483?

A flaw exists within the runScript function in Tunnelblick versions 3.3beta20 and earlier that allows local users to exploit a race condition. By manipulating a script file, these users can gain elevated privileges on the system, potentially leading to unauthorized actions and compromising system integrity. This vulnerability emphasizes the necessity for secure coding practices to mitigate race conditions effectively.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2012-3483 : Local privilege escalation vulnerability in Tunnelblick by OpenVPN Technologies