VYPR

Arq

by Arqbackup

CVEs (2)

  • CVE-2017-16895HigDec 1, 2017
    risk 0.54cvss 7.8epss 0.01

    The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.

  • CVE-2017-15357HigDec 1, 2017
    risk 0.51cvss 7.4epss 0.01

    The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.