CVE-2019-6238

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/10/2020
Last modified:
30/10/2020

Description

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. Processing a maliciously crafted package may lead to arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.14.4 (excluding)


References to Advisories, Solutions, and Tools