Jump to content
Not connected, Your IP: 3.147.74.33
Sign in to follow this  
lambrinoul

Viscosity or Tunnelblick security risk?

Recommended Posts


I thought i had posted my last question for the day but then I came across this post on a blog which I wanted to share on this forum.


 


When either Viscosity or Tunnelblick is installed, an unprivileged user can elevate permissions to become root (the Administrator user). EDIT by Staff: only true for obsolete versions


 


http://blog.zx2c4.com/791


 


 


I would appreciate if the knowledgable staff could shed a light on the above.


Share this post


Link to post

Hello,

 

the reported Tunnelblick vulnerability (affecting 3.2.8 and earlier versions) was quickly addressed already in Tunnelblick 3.3experimental, and has been ultimately fixed on Tunnelblick 3.3beta22 on 12-Sep-2012, i.e. just a few weeks after the notification. http://code.google.com/p/tunnelblick/wiki/RlsNotes

 

About Viscosity, on the very same page which you provided the link of, it is written that Jason Donenfeld reported the vulnerability to the vendor on 11-Aug-2012 and the vendor corrected it on 30-Aug-2012.

 

You should never run obsolete program versions: vulnerabilities are discovered every day and it's important to address them expeditiously.

 

Also keep your OS X up to date (although Apple is sometimes slow in addressing vulnerabilities): dozens of vulnerabilities are discovered every month. The work of those who discover vulnerabilities and notify the programmers about vulnerabilities is invaluable.

 

Kind regards

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image
Sign in to follow this  

×
×
  • Create New...