CVE-2012-3485: Google Tunnelblick
High severity, CVSS 7.2. EPSS: 3.8% chance of exploitation in the next 30 days.
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call.
Affected products
- Google Tunnelblick: up to and including 3.3beta20
Published 2012-08-26. Last modified 2026-06-16.