CVE-2012-4676

Tunnelblick <3.3beta20 - Local File Deletion

Title source: llm
STIX 2.1

Description

The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary files by constructing a (1) symlink or (2) hard link, a different vulnerability than CVE-2012-3485.

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/08/14/1

Scores

EPSS 0.0019
EPSS Percentile 8.3%

Details

CWE
CWE-59
Status published
Products (1)
google/tunnelblick < 3.3beta20
Published Aug 26, 2012
Tracked Since Feb 18, 2026