CVE-2017-2372

CWE-119Buffer Overflow7 documents5 sources
Severity
8.8HIGH
EPSS
0.8%
top 25.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 17

Description

An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GarageBand project file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDapple/garageband10.1.4
NVDapple/logic_pro_x10.2.4

🔴Vulnerability Details

2
GHSA
GHSA-cwj8-ghw3-498v: An issue was discovered in certain Apple products2022-05-17
CVEList
CVE-2017-2372: An issue was discovered in certain Apple products2017-02-20

📋Vendor Advisories

2
Apple
CVE-2017-2372: Logic Pro X 10.32017-01-18
Apple
CVE-2017-2372: GarageBand 10.1.52017-01-18

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability2017-02-14
Talos
Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability2017-02-14
CVE-2017-2372 (HIGH CVSS 8.8) | An issue was discovered in certain | cvebase.io