mirror of
https://github.com/chainguard-dev/osquery-defense-kit
synced 2025-02-16 17:37:06 +00:00
Merge pull request #305 from tstromberg/acrobat-reader
Detect vulnerable versions of Acrobat Reader
This commit is contained in:
commit
a9eba00fb6
27
policy/vulnerable-acrobat-reader.sql
Normal file
27
policy/vulnerable-acrobat-reader.sql
Normal file
@ -0,0 +1,27 @@
|
||||
-- Vulnerable version of Adobe Acrobat Reader is installed
|
||||
--
|
||||
-- References:
|
||||
-- * https://helpx.adobe.com/security/products/acrobat/apsb23-34.html
|
||||
--
|
||||
-- tags: persistent state filesystem
|
||||
-- platform: darwin
|
||||
SELECT
|
||||
name,
|
||||
path,
|
||||
bundle_version,
|
||||
TRIM(REGEX_MATCH (bundle_version, "^(\d+)\.", 1)) AS major,
|
||||
TRIM(REGEX_MATCH (bundle_version, "\.(\d+)$", 1)) AS patch
|
||||
FROM
|
||||
apps
|
||||
WHERE
|
||||
name LIKE "%Acrobat%"
|
||||
AND (
|
||||
(
|
||||
major = "23"
|
||||
AND CAST(patch AS integer) < 20285
|
||||
)
|
||||
OR (
|
||||
major = "20"
|
||||
AND CAST(patch AS integer) < 30517
|
||||
)
|
||||
)
|
Loading…
Reference in New Issue
Block a user