Vulnerability Description
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sparklabs | Viscosity | 1.4.1 |
References
- http://www.exploit-db.com/exploits/24579ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/55002Third Party AdvisoryVDB Entry
- https://packetstormsecurity.com/files/120643/Viscosity-setuid-set-ViscosityHelpeExploitThird Party AdvisoryVDB Entry
- https://www.sparklabs.com/viscosity/releasenotes/mac/Release NotesVendor Advisory
- http://www.exploit-db.com/exploits/24579ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/55002Third Party AdvisoryVDB Entry
- https://packetstormsecurity.com/files/120643/Viscosity-setuid-set-ViscosityHelpeExploitThird Party AdvisoryVDB Entry
- https://www.sparklabs.com/viscosity/releasenotes/mac/Release NotesVendor Advisory
FAQ
What is CVE-2012-4284?
CVE-2012-4284 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute...
How severe is CVE-2012-4284?
CVE-2012-4284 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2012-4284?
Check the references section above for vendor advisories and patch information. Affected products include: Sparklabs Viscosity.