Описание
Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app.
Ссылки
- ExploitThird Party Advisory
- PatchRelease NotesVendor Advisory
- ExploitThird Party Advisory
- PatchRelease NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 75 (исключая)
Одновременно
cpe:2.3:a:sketch:sketch:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06708
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Sketch before 75 mishandles external library feeds.
EPSS
Процентиль: 91%
0.06708
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434