This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. Extracting a zip file containing a symbolic link to an endpoint in an NFS mount that is attacker controlled may bypass Gatekeeper.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-18046 This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. Extracting a zip file containing a symbolic link to an endpoint in an NFS mount that is attacker controlled may bypass Gatekeeper.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2024-08-04T21:24:29.528Z

Reserved: 2019-02-18T00:00:00

Link: CVE-2019-8656

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-27T20:15:17.080

Modified: 2024-11-21T04:50:14.383

Link: CVE-2019-8656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.