I am writing this as a heads up to the community, there seems to be a privilege escalation vulnerability in opensnitch. The original author told me to go ahead and request the CVE as they do not believe it to have enough impact to matter and they do not plan to patch it out. I hope it is not impactful as I do not wish security incidents on anyone. I am releasing it to at least notify users that it exists and could affect them. I am not waiting since I was informed a patch would not happen. I am in the process of requesting the CVE right now (Aug 19 01:03 UTC). The write up and PoC will be made public sometime today or tomorrow (Aug 19th-20th).
I am writing this as a heads up to the community, there seems to be a privilege escalation vulnerability in opensnitch. The original author told me to go ahead and request the CVE as they do not believe it to have enough impact to matter and they do not plan to patch it out. I hope it is not impactful as I do not wish security incidents on anyone. I am releasing it to at least notify users that it exists and could affect them. I am not waiting since I was informed a patch would not happen. I am in the process of requesting the CVE right now (Aug 19 01:03 UTC). The write up and PoC will be made public sometime today or tomorrow (Aug 19th-20th).