CVE-2017-2374
published 2017-02-20CVE-2017-2374: An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote…
PriorityP335high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.52%
71.7th percentile
An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted GarageBand project file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | garageband | <= 10.1.5 | — |
| apple | garageband | — | — |
| apple | logic_pro_x | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-2374: Logic Pro X 10.3.1
vendor_apple·2017-02-21·CVSS 7.8
CVE-2017-2374 [HIGH] CVE-2017-2374: Logic Pro X 10.3.1
Apple Security Update: About the security content of Logic Pro X 10.3.1
Product: Logic Pro X
Version: 10.3.1
CVE: CVE-2017-2374
Component: Projects
Impact: Opening a maliciously crafted GarageBand project file may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
Apple
CVE-2017-2374: GarageBand 10.1.6
vendor_apple·2017-02-13·CVSS 7.8
CVE-2017-2374 [HIGH] CVE-2017-2374: GarageBand 10.1.6
Apple Security Update: About the security content of GarageBand 10.1.6
Product: GarageBand
Version: 10.1.6
CVE: CVE-2017-2374
Component: Projects
Impact: Opening a maliciously crafted GarageBand project file may lead to arbitrary code execution
Description: A memory corruption issue was addressed through improved memory handling.
GHSA
GHSA-r42w-3527-hfjh: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-17
CVE-2017-2374 [HIGH] CWE-119 GHSA-r42w-3527-hfjh: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted GarageBand project file.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability
blogs_talos·2017-02-14·CVSS 8.8
CVE-2017-2372 [HIGH] Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability
Discovered by Tyler Bohan of Cisco Talos
## Overview Talos is disclosingTALOS-2016-0262(CVE-2017-2372) andTALOS-2017-0275(CVE-2017-2374), an out of bounds write vulnerability in Apple GarageBand. GarageBand is a music creation program, allowing users to create and edit music easily and effectively from their Mac computer. GarageBand is installed by default on all Mac computers so there is a significant number of potential victims. This issue was partially resolved on 1/18/17 with a patch which addressed CVE-2017-2372, the patch released on 2/13/17 addressed CVE-2017-2374 resolving the issue.
This particular vulnerability is the result of the way the application parses the proprietary file format used for GarageBand files, .band. The format is broken into chunks with a specific length fie
Talos
Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability
blogs_talos·2017-02-14·CVSS 8.8
CVE-2017-2372 [HIGH] Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability
## Vulnerability Spotlight: Apple Garage Band Out of Bounds Write Vulnerability
Discovered by Tyler Bohan of Cisco Talos
## Overview Talos is disclosing TALOS-2016-0262 ( CVE-2017-2372 ) and TALOS-2017-0275 ( CVE-2017-2374 ), an out of bounds write vulnerability in Apple GarageBand. GarageBand is a music creation program, allowing users to create and edit music easily and effectively from their Mac computer. GarageBand is installed by default on all Mac computers so there is a significant number of potential victims. This issue was partially resolved on 1/18/17 with a patch which addressed CVE-2017-2372, the patch released on 2/13/17 addressed CVE-2017-2374 resolving the issue.
This particular vulnerability is the result of the way the application parses the proprietary file format used
http://www.securityfocus.com/bid/96171http://www.securitytracker.com/id/1037868http://www.talosintelligence.com/reports/TALOS-2017-0275/https://support.apple.com/HT207518http://www.securityfocus.com/bid/96171http://www.securitytracker.com/id/1037868http://www.talosintelligence.com/reports/TALOS-2017-0275/https://support.apple.com/HT207518
2017-02-20
Published