CVE-2012-3485: Google Tunnelblick

High severity, CVSS 7.2. EPSS: 3.8% chance of exploitation in the next 30 days.

Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call.

Affected products

  • Google Tunnelblick: up to and including 3.3beta20

Published 2012-08-26. Last modified 2026-06-16.