CVE-2017-2374

CWE-119Buffer Overflow7 documents5 sources
Severity
7.8HIGH
EPSS
0.6%
top 30.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 20
Latest updateMay 17

Description

An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted GarageBand project file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDapple/garageband10.1.5

🔴Vulnerability Details

2
GHSA
GHSA-r42w-3527-hfjh: An issue was discovered in certain Apple products2022-05-17
CVEList
CVE-2017-2374: An issue was discovered in certain Apple products2017-02-20

📋Vendor Advisories

2
Apple
CVE-2017-2374: Logic Pro X 10.3.12017-02-21
Apple
CVE-2017-2374: GarageBand 10.1.62017-02-13

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability2017-02-14
Talos
Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability2017-02-14
CVE-2017-2374 (HIGH CVSS 7.8) | An issue was discovered in certain | cvebase.io