First published: Mon Feb 20 2017(Updated: )
An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GarageBand project file.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Logic Pro | <=10.2.4 | |
Apple GarageBand | <=10.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2372 is considered a high severity vulnerability due to its potential to allow remote code execution.
To fix CVE-2017-2372, update GarageBand to version 10.1.5 or later and Logic Pro X to version 10.3 or later.
CVE-2017-2372 affects Apple GarageBand versions before 10.1.5 and Logic Pro X versions before 10.3.
CVE-2017-2372 can enable remote attackers to execute arbitrary code or cause a denial of service through memory corruption.
There have been no confirmed reports of CVE-2017-2372 being actively exploited in the wild as of now.