HTTP: Apple XAR Archive Symlink Parsing Arbitrary File Write

This signature detects attempts to exploit a known vulnerability against Apple XAR command. A successful attack can lead to local file inclusion.

Extended Description

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.

Affected Products

Apple macos

Short Name
HTTP:STC:APPLE-XAR-ARB-FW-LFI
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apple Arbitrary Archive CVE-2022-22582 File Parsing Symlink Write XAR
Release Date
04/25/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3648
False Positive
Unknown
Vendors

Apple

Found a potential security threat?