First published: Sun Aug 26 2012(Updated: )
Race condition in Tunnelblick 3.3beta20 and earlier allows local users to kill unintended processes by waiting for a specific PID value to be assigned to a target process.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Tunnelblick | <=3.3beta20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3487 has a medium severity level as it involves a race condition that can be exploited by local users.
To fix CVE-2012-3487, upgrade Tunnelblick to a version later than 3.3beta20.
CVE-2012-3487 affects users of Tunnelblick versions up to and including 3.3beta20.
An attacker can potentially kill unintended processes on the system by exploiting the race condition in CVE-2012-3487.
CVE-2012-3487 is classified as a local vulnerability, meaning it can only be exploited by local users on the affected system.