First published: Mon Dec 31 2018(Updated: )
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute. This issue affects osquery prior to v3.2.7
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Osquery | <3.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.