Launchpad.net

CVE 2016-7742

An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "xar" component, which allows remote attackers to execute arbitrary code via a crafted archive that triggers use of uninitialized memory locations.

See the CVE page on Mitre.org for more details.

References