PT-2023-21435 · Apple · Garageband

·

CVE-2023-27938

·

Publicado

2023-05-08

·

Atualizado

2023-07-27

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GarageBand versions prior to 10.4.8
Description An out-of-bounds read issue was addressed with improved input validation. Parsing a maliciously crafted MIDI file may lead to an unexpected application termination or arbitrary code execution.
Recommendations For versions prior to 10.4.8, update to GarageBand for macOS 10.4.8 to resolve the issue. As a temporary workaround, consider avoiding the use of maliciously crafted MIDI files until the update is applied.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27938
ZDI-23-644

Produtos afetados

Garageband