CVE-2019-13013
Last modified
CVE-2019-13013 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Obdev | Little Snitch | >= 4.3.0, <= 4.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13013?
How severe is CVE-2019-13013?
How do I fix CVE-2019-13013?
Are you affected by CVE-2019-13013?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
