VYPR

Arq

by Arq

CVEs (3)

  • CVE-2017-16945HigJan 31, 2018
    risk 0.54cvss 7.8epss 0.01

    The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted restore path.

  • CVE-2017-16928HigJan 31, 2018
    risk 0.54cvss 7.8epss 0.01

    The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted update URL, as demonstrated by file:///tmp/blah/Arq.zip.

  • CVE-2017-15357HigDec 1, 2017
    risk 0.51cvss 7.4epss 0.01

    The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.