Description
Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory containing code executed by root.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-5372 | Little Snitch version 4.5.1 and older changed ownership of a directory path controlled by the user. This allowed the user to escalate to root by linking the path to a directory containing code executed by root. |
References
| Link | Providers |
|---|---|
| https://obdev.at/cve/2020-13095-t46oXJJOwz.html |
|
History
No history.
Status: PUBLISHED
Assigner: obdev
Published:
Updated: 2024-08-04T12:11:19.272Z
Reserved: 2020-05-15T00:00:00.000Z
Link: CVE-2020-13095
No data.
Status : Modified
Published: 2020-06-30T17:15:10.610
Modified: 2024-11-21T05:00:39.563
Link: CVE-2020-13095
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD