"-Synchronized-Data."

This commit is contained in:
CVE Team 2022-01-02 01:01:00 +00:00
parent fa896543fe
commit 1e3a1ffc99
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743

View File

@ -34,7 +34,7 @@
"description_data": [
{
"lang": "eng",
"value": "An issue discovered in sketch before version 75,that allows for library feeds to be used to bypass file quarantine which results in remote code execution."
"value": "Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app."
}
]
},