evilsocket / evilsocket/opensnitch

[LOCAL PRIV ESC VULN] There is a local privilege escalation in this software

Open
#1,653 8 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Python
Stars
14.1k
Forks
665
PR merge metrics
No merged PRs in 30d

Description

I am writing this as a heads up to the community, there seems to be a privilege escalation vulnerability in opensnitch. The original author told me to go ahead and request the CVE as they do not believe it to have enough impact to matter and they do not plan to patch it out. I hope it is not impactful as I do not wish security incidents on anyone. I am releasing it to at least notify users that it exists and could affect them. I am not waiting since I was informed a patch would not happen. I am in the process of requesting the CVE right now (Aug 19 01:03 UTC). The write up and PoC will be made public sometime today or tomorrow (Aug 19th-20th).

Contributor guide

No contributing guide indexed for this repository

Research direction

The report names no files, tests, or entry points; start with the promised public write-up and PoC, then trace the affected OpenSnitch path. Done would require a maintainer-confirmed reproduction and an agreed remediation, neither of which is specified here.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.