CVE-2017-2374: Buffer Overflow
An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted GarageBand project file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2374?
CVE-2017-2374 has been rated as having high severity due to its potential to execute arbitrary code or cause denial of service.
How do I fix CVE-2017-2374?
To fix CVE-2017-2374, update GarageBand to version 10.1.6 or later.
What types of attacks can be executed using CVE-2017-2374?
CVE-2017-2374 can be exploited by remote attackers to execute arbitrary code or cause application crashes.
Which versions of GarageBand are affected by CVE-2017-2374?
CVE-2017-2374 affects GarageBand versions prior to 10.1.6.
Is it possible for users to be affected by CVE-2017-2374 without their knowledge?
Yes, users can be affected by CVE-2017-2374 if they open a crafted GarageBand project file from an untrusted source.