CVE-2017-7151Race Condition in Apple Itunes

CWE-362Race Condition9 documents4 sources
Severity
7.0HIGHNVD
EPSS
0.3%
top 51.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateMay 14

Description

A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages5 packages

NVDapple/mac_os_x10.13.310.13.4+1
NVDapple/tvos< 11.2
NVDapple/itunes< 12.7.2
NVDapple/watchos< 4.2
NVDapple/iphone_os< 11.2

🔴Vulnerability Details

2
GHSA
GHSA-vjwr-279m-hhv6: A race condition was addressed with additional validation2022-05-14
CVEList
CVE-2017-7151: A race condition was addressed with additional validation2019-04-03

📋Vendor Advisories

6
Apple
CVE-2017-7151: macOS High Sierra 10.13.4, Security Update 2018-002 Sierra, and Security Update 2018-002 El Capitan2018-03-29
Apple
CVE-2017-7151: macOS High Sierra 10.13.2, Security Update 2017-002 Sierra, and Security Update 2017-005 El Capitan2017-12-06
Apple
CVE-2017-7151: iTunes 12.7.2 for Windows2017-12-06
Apple
CVE-2017-7151: watchOS 4.22017-12-05
Apple
CVE-2017-7151: tvOS 11.22017-12-04
CVE-2017-7151 — Race Condition in Apple Itunes | cvebase