Input validation error in macOS - CVE-2021-30833

 

Input validation error in macOS - CVE-2021-30833

Published: October 27, 2021 / Updated: February 16, 2022


Vulnerability identifier: #VU57745
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30833
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input when processing xar archives. A remote attacker can create a specially crafted .xar archive, trick the victim into opening it and overwrite arbitrary files on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Affected software

macOS
Gentoo Linux
app-arch/xar

How to mitigate CVE-2021-30833

Install updates from vendor's website.

macOS - addressed in versions 12.0.1 21A559, 10.15.7 19H1519, 11.6.1 20G224
app-arch/xar - update to 1.8.0.0.487.100.1

External References

Related Security Bulletins