Lucene search

K
cveObdevCVE-2016-8661
HistoryNov 15, 2016 - 3:59 p.m.

CVE-2016-8661

2016-11-1515:59:00
CWE-119
obdev
web.nvd.nist.gov
23
cve-2016-8661
little snitch
buffer overflow
eop
unauthorised access
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

33.3%

Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauthorised ring0 access to the operating system. The buffer overflow is related to insufficient checking of parameters to the “OSMalloc” and “copyin” kernel API calls.

Affected configurations

Nvd
Node
obdevlittle_snitchMatch3.0
OR
obdevlittle_snitchMatch3.0.1
OR
obdevlittle_snitchMatch3.0.2
OR
obdevlittle_snitchMatch3.0.3
OR
obdevlittle_snitchMatch3.0.4
OR
obdevlittle_snitchMatch3.1
OR
obdevlittle_snitchMatch3.1.1
OR
obdevlittle_snitchMatch3.3
OR
obdevlittle_snitchMatch3.3.1
OR
obdevlittle_snitchMatch3.3.2
OR
obdevlittle_snitchMatch3.3.3
OR
obdevlittle_snitchMatch3.3.4
OR
obdevlittle_snitchMatch3.4
OR
obdevlittle_snitchMatch3.4.1
OR
obdevlittle_snitchMatch3.4.2
OR
obdevlittle_snitchMatch3.5
OR
obdevlittle_snitchMatch3.5.1
OR
obdevlittle_snitchMatch3.5.2
OR
obdevlittle_snitchMatch3.5.3
OR
obdevlittle_snitchMatch3.6
OR
obdevlittle_snitchMatch3.6.1
VendorProductVersionCPE
obdevlittle_snitch3.0cpe:2.3:a:obdev:little_snitch:3.0:*:*:*:*:*:*:*
obdevlittle_snitch3.0.1cpe:2.3:a:obdev:little_snitch:3.0.1:*:*:*:*:*:*:*
obdevlittle_snitch3.0.2cpe:2.3:a:obdev:little_snitch:3.0.2:*:*:*:*:*:*:*
obdevlittle_snitch3.0.3cpe:2.3:a:obdev:little_snitch:3.0.3:*:*:*:*:*:*:*
obdevlittle_snitch3.0.4cpe:2.3:a:obdev:little_snitch:3.0.4:*:*:*:*:*:*:*
obdevlittle_snitch3.1cpe:2.3:a:obdev:little_snitch:3.1:*:*:*:*:*:*:*
obdevlittle_snitch3.1.1cpe:2.3:a:obdev:little_snitch:3.1.1:*:*:*:*:*:*:*
obdevlittle_snitch3.3cpe:2.3:a:obdev:little_snitch:3.3:*:*:*:*:*:*:*
obdevlittle_snitch3.3.1cpe:2.3:a:obdev:little_snitch:3.3.1:*:*:*:*:*:*:*
obdevlittle_snitch3.3.2cpe:2.3:a:obdev:little_snitch:3.3.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 211

CNA Affected

[
  {
    "product": "Little Snitch version 3.0 through 3.6.1",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Little Snitch version 3.0 through 3.6.1"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

33.3%

Related for CVE-2016-8661