CVE-2019-13013 Vulnerability Details

  /     /     /  

CVE-2019-13013 Metadata Quick Info

CVE Published: 23/08/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: obdev | Vendor: n/a | Product: Little Snitch
Status : PUBLISHED

CVE-2019-13013 Description

Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-264
CWE Name: CWE-264: Permissions, Privileges, and Access Controls
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).