CVE-2009-2198: Medium severity apple garageband vulnerability
Published Aug 4, 2009
·Updated
Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users.
Affected Software
5 affected components
Apple GarageBand=4.1.2
Apple GarageBand=4.1.1
Apple GarageBand<=5.0.2
Apple GarageBand=5.0.1
Apple GarageBand=5.0
Remediation
Patch Available
Patch Available
Event History
Aug 4, 2009
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2198?
CVE-2009-2198 is considered a moderate severity vulnerability due to its potential to enable user tracking.
2
How do I fix CVE-2009-2198?
To mitigate CVE-2009-2198, users should upgrade to Apple GarageBand version 5.1 or later.
3
What versions of Apple GarageBand are affected by CVE-2009-2198?
CVE-2009-2198 affects Apple GarageBand versions 4.1.1 through 5.0.2.
4
What impact does CVE-2009-2198 have on users?
CVE-2009-2198 allows remote web servers to track users more easily by accepting all cookies regardless of domain.
5
Is my device vulnerable to CVE-2009-2198?
If you are using Apple GarageBand version 5.0.2 or earlier, your device is vulnerable to CVE-2009-2198.