vendor:
Libsafe
by:
SecurityFocus
7.5
CVSS
HIGH
Race Condition
362
CWE
Product Name: Libsafe
Affected Version From: Libsafe 2.0-16
Affected Version To: Libsafe 2.0-16
Patch Exists: YES
Related CWE: N/A
CPE: a:libsafe:libsafe:2.0-16
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004
Libsafe Security Failsafe Bypass
A race condition vulnerability has been reported in Libsafe 2.0-16 that may allow Libsafe security failsafe mechanisms to be bypassed. This is due to an implementation error in Libsafe that does not present a security risk unless there is a memory corruption vulnerability in a multi-threaded application on an affected computer.
Mitigation:
Ensure that Libsafe is updated to the latest version and that multi-threaded applications are regularly tested for memory corruption vulnerabilities.