CVE-2023-25394

Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:getvideostream:videostream:0.4.3:*:*:*:*:macos:*:*
cpe:2.3:a:getvideostream:videostream:0.5.0:*:*:*:*:macos:*:*

History

28 Aug 2023, 18:15

Type Values Removed Values Added
References
  • (CERT-VN) https://www.kb.cert.org/vuls/id/757109 -

25 May 2023, 17:57

Type Values Removed Values Added
References (MISC) https://danrevah.github.io/2023/05/03/CVE-2023-25394-VideoStream-LPE/ - (MISC) https://danrevah.github.io/2023/05/03/CVE-2023-25394-VideoStream-LPE/ - Exploit, Third Party Advisory
References (MISC) https://getvideostream.com/ - (MISC) https://getvideostream.com/ - Product
First Time Getvideostream
Getvideostream videostream
CPE cpe:2.3:a:getvideostream:videostream:0.5.0:*:*:*:*:macos:*:*
cpe:2.3:a:getvideostream:videostream:0.4.3:*:*:*:*:macos:*:*
CWE CWE-367
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0

17 May 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-17 00:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-25394

Mitre link : CVE-2023-25394

CVE.ORG link : CVE-2023-25394


JSON object : View

Products Affected

getvideostream

  • videostream
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition