Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauthorised ring0 access to the operating system. The buffer overflow is related to insufficient checking of parameters to the "OSMalloc" and "copyin" kernel API calls.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: obdev
Published: 2016-11-15T15:00:00
Updated: 2024-08-06T02:27:41.325Z
Reserved: 2016-10-14T00:00:00
Link: CVE-2016-8661
Vulnrichment
No data.
NVD
Status : Modified
Published: 2016-11-15T15:59:00.180
Modified: 2024-11-21T02:59:47.510
Link: CVE-2016-8661
Redhat
No data.