Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-08-26T19:00:00

Updated: 2024-08-06T20:05:12.644Z

Reserved: 2012-06-14T00:00:00

Link: CVE-2012-3485

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-08-26T19:55:02.043

Modified: 2013-12-13T05:03:03.297

Link: CVE-2012-3485

cve-icon Redhat

No data.