CVE-2019-8656: Medium severity macos mojave vulnerability
autofs. This was addressed with additional checks by Gatekeeper on files mounted through a network share.
Other sources
This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. Extracting a zip file containing a symbolic link to an endpoint in an NFS mount that is attacker controlled may bypass Gatekeeper.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8693
- CVE-2019-8656
- CVE-2018-19860
- CVE-2019-9506
- CVE-2020-10135
- CVE-2019-8661
- CVE-2019-8646
- CVE-2019-8660
- CVE-2019-8675
- CVE-2019-8696
- CVE-2019-8539
- CVE-2019-8697
- CVE-2019-8648
- CVE-2019-8663
- CVE-2019-8702
- CVE-2019-8695
- CVE-2019-8691
- CVE-2019-8692
- CVE-2018-16860
- CVE-2019-8694
- CVE-2019-13118
- CVE-2019-8662
- CVE-2019-8670
- CVE-2019-8701
- CVE-2019-8667
- CVE-2019-8657
- CVE-2019-8690
- CVE-2019-8649
- CVE-2019-8658
- CVE-2019-8644
- CVE-2019-8666
- CVE-2019-8669
- CVE-2019-8671
- CVE-2019-8672
- CVE-2019-8673
- CVE-2019-8676
- CVE-2019-8677
- CVE-2019-8678
- CVE-2019-8679
- CVE-2019-8680
- CVE-2019-8681
- CVE-2019-8683
- CVE-2019-8684
- CVE-2019-8685
- CVE-2019-8686
- CVE-2019-8687
- CVE-2019-8688
- CVE-2019-8689
Frequently Asked Questions
What is CVE-2019-8656?
CVE-2019-8656 is a vulnerability found in autofs in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, and Security Update 2019-004 Sierra.
How does CVE-2019-8656 affect Apple Mac OS X?
CVE-2019-8656 affects Apple Mac OS X versions up to and excluding 10.14.6.
How does CVE-2019-8656 affect Apple macOS Mojave?
CVE-2019-8656 affects Apple macOS Mojave versions up to and excluding 10.14.6.
What is the severity of CVE-2019-8656?
The severity of CVE-2019-8656 is medium with a CVSS score of 5.5.
How can I fix CVE-2019-8656?
To fix CVE-2019-8656, update to macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, or Security Update 2019-004 Sierra.