CVE-2017-2372: Buffer Overflow
An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GarageBand project file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2372?
CVE-2017-2372 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2017-2372?
To fix CVE-2017-2372, update GarageBand to version 10.1.5 or later and Logic Pro X to version 10.3 or later.
What products are affected by CVE-2017-2372?
CVE-2017-2372 affects Apple GarageBand versions before 10.1.5 and Logic Pro X versions before 10.3.
What type of attacks can CVE-2017-2372 enable?
CVE-2017-2372 can enable remote attackers to execute arbitrary code or cause a denial of service through memory corruption.
Is CVE-2017-2372 currently being exploited in the wild?
There have been no confirmed reports of CVE-2017-2372 being actively exploited in the wild as of now.