CVE-2012-4455

openCryptoki 2.4.1 - Local Arbitrary File Write via Symlink Attack on Lock Files

Title source: llm
STIX 2.1

Description

openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.

References (12)

Core 12
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/09/2
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/25/5
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50702
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/55627
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/27/2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/78943
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/20/6
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=730636
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/07/2
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/09/07/6

Scores

EPSS 0.0036
EPSS Percentile 27.6%

Details

CWE
CWE-59
Status published
Products (1)
opencryptoki_project/opencryptoki 2.4.1
Published Oct 10, 2012
Tracked Since Feb 18, 2026