PT-2024-19395 · Xadmaster · Xadmaster

Coca-Cola-Light

·

Published

2024-04-30

·

Updated

2024-04-30

·

CVE-2024-22405

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions XADMaster versions prior to 1.10.8
Description XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted zip archive, XADMaster may not apply the quarantine attribute correctly, potentially circumventing Gatekeeper checks on the system. This issue affects only macOS installations.
Recommendations For versions prior to 1.10.8, upgrade to the latest version, specifically 1.10.8 or later, to resolve the issue. There are no known workarounds for this issue.

Exploit

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-22405
GHSA-XG3C-R7W5-7XW2

Affected Products

Xadmaster