CVE-2019-13013

Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:obdev:little_snitch:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:03

Type Values Removed Values Added
References (MISC) https://obdev.at/cve/2019-13013-OSv2mEFD3z.html - Mitigation, Vendor Advisory () https://obdev.at/cve/2019-13013-OSv2mEFD3z.html -

08 Sep 2021, 17:22

Type Values Removed Values Added
CPE cpe:2.3:o:apple:mac_os:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

Information

Published : 2019-08-23 17:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-13013

Mitre link : CVE-2019-13013

CVE.ORG link : CVE-2019-13013


JSON object : View

Products Affected

obdev

  • little_snitch

apple

  • macos
CWE
CWE-862

Missing Authorization

CWE-264

Permissions, Privileges, and Access Controls