Vulnerabilities > Arqbackup > ARQ > 5.5

DATE CVE VULNERABILITY TITLE RISK
2017-12-01 CVE-2017-16895 Incorrect Permission Assignment for Critical Resource vulnerability in Arqbackup ARQ
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.
local
low complexity
arqbackup CWE-732
7.2
2017-12-01 CVE-2017-15357 Race Condition vulnerability in Arqbackup ARQ
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.
6.9