Google Drive 60.0

CPE Details

Google Drive 60.0
60.0
2022-10-19
12h04 +00:00
2022-10-19
12h59 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:google:drive:60.0:*:*:*:*:-:*:*

Informations

Vendor

google

Product

drive

Version

60.0

Target Software

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-3421 2022-10-16 22h00 +00:00 An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a binary in that directory with execute permissions and set its setuid bit. Since the attacker owns the directory, the attacker can replace the binary with a symlink, causing the installer to set the setuid bit on the symlink. When the symlink is executed, it will run with root permissions. We recommend upgrading past version 64.0
7.3
Haute