PT-2021-18900 · Apple · Apple Macos
Richard Warren
·
Published
2021-10-25
·
Updated
2022-10-11
·
CVE-2021-30833
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 12.0.1
Description
The issue allows an attacker to write arbitrary files by unpacking a maliciously crafted archive. This is possible due to insufficient checks, which have been improved in the fixed version.
Recommendations
For versions prior to 12.0.1, update to macOS Monterey 12.0.1 to resolve the issue. As a temporary workaround, consider avoiding the unpacking of archives from untrusted sources until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apple Macos