MidnightBSD

Advisories for objective-see

CVE-2018-10404 MEDIUM

An issue was discovered in Objective-See KnockKnock, LuLu, TaskExplorer, WhatsYourSign, and procInfo. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-295,

Products Affected

Vendor Product Version
objective-see procinfo -
objective-see lulu *
objective-see taskexplorer *
objective-see whatsyoursign *
objective-see knockknock *