CVE Vulnerabilities

CVE-2025-43711

Incomplete Cleanup

Published: Jul 05, 2025 | Modified: Jul 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Potential Mitigations

References