CVE-2016-8661
Summary
| CVE | CVE-2016-8661 |
|---|---|
| State | PUBLISHED |
| Assigner | obdev |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-11-15 15:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauthorised ring0 access to the operating system. The buffer overflow is related to insufficient checking of parameters to the "OSMalloc" and "copyin" kernel API calls. |
Risk And Classification
Primary CVSS: v3.0 8.4 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.000520000 probability, percentile 0.160530000 (date 2026-05-10)
Problem Types: CWE-119 | escalation of privileges
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 8.4 | HIGH | CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Obdev | Little Snitch | 3.0 | All | All | All |
| Application | Obdev | Little Snitch | 3.0.1 | All | All | All |
| Application | Obdev | Little Snitch | 3.0.2 | All | All | All |
| Application | Obdev | Little Snitch | 3.0.3 | All | All | All |
| Application | Obdev | Little Snitch | 3.0.4 | All | All | All |
| Application | Obdev | Little Snitch | 3.1 | All | All | All |
| Application | Obdev | Little Snitch | 3.1.1 | All | All | All |
| Application | Obdev | Little Snitch | 3.3 | All | All | All |
| Application | Obdev | Little Snitch | 3.3.1 | All | All | All |
| Application | Obdev | Little Snitch | 3.3.2 | All | All | All |
| Application | Obdev | Little Snitch | 3.3.3 | All | All | All |
| Application | Obdev | Little Snitch | 3.3.4 | All | All | All |
| Application | Obdev | Little Snitch | 3.4 | All | All | All |
| Application | Obdev | Little Snitch | 3.4.1 | All | All | All |
| Application | Obdev | Little Snitch | 3.4.2 | All | All | All |
| Application | Obdev | Little Snitch | 3.5 | All | All | All |
| Application | Obdev | Little Snitch | 3.5.1 | All | All | All |
| Application | Obdev | Little Snitch | 3.5.2 | All | All | All |
| Application | Obdev | Little Snitch | 3.5.3 | All | All | All |
| Application | Obdev | Little Snitch | 3.6 | All | All | All |
| Application | Obdev | Little Snitch | 3.6.1 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Little Snitch Version 3.0 Through 3.6.1 | affected Little Snitch version 3.0 through 3.6.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [DefCon 2016] I got 99 Problems, but Little Snitch ain’t one! // Speaker Deck | af854a3a-2127-422b-91ae-364da2661108 | speakerdeck.com | |
| Little Snitch CVE-2016-8661 Local Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.