mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-23 02:29:40 +02:00
18 lines
783 B
Markdown
18 lines
783 B
Markdown
### [CVE-2012-4454](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4454)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://opencryptoki.git.sourceforge.net/git/gitweb.cgi?p=opencryptoki/opencryptoki%3Ba=commitdiff%3Bh=b7fcb3eb0319183348f1f4fb90ede4edd6487c30
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|