OSV 1.4.0 · unreviewed · 修改于 2023-08-08 23:31
发布时间
2022-02-20 08:00
GitHub 审查时间
—
NVD 发布时间
2022-02-19 11:15
源文件
advisories/unreviewed/2022/02/GHSA-rg7g-mrvx-gg82/GHSA-rg7g-mrvx-gg82.json
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables entitlements. An attacker can exploit this by creating a malicious .dylib file that can be executed via the DYLD_INSERT_LIBRARIES environment variable.
该公告没有提供结构化的受影响软件包信息。