CVE-2012-3485
38Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 3.8%
from disclosure to weapon0 days
Published on NVDAug 26
1st PoCAug 11
metasploitAug 11
exploitation probability
3.8%top 11% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/24578unverifiedexploitdbwww.exploit-db.com/exploits/20443unverifiedexploitdbwww.exploit-db.com/exploits/24578unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/fulldisclosure/2012-08/0122.htmlhttp://code.google.com/p/tunnelblick/issues/detail?id=212http://git.zx2c4.com/Pwnnel-Blicker/tree/pwnnel-blicker-for-kids.shhttp://www.exploit-db.com/exploits/24578http://www.openwall.com/lists/oss-security/2012/08/14/1