First published: Thu Sep 12 2024(Updated: )
A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.
Credit: product-security@apple.com Mads Ball Bocheng Xiang with Fudan University Willy R. Vasquez The University of Texas at AustinSrikanth Narayanaraju
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.13.3 | 12.13.3 |
Apple TV | <1.5.0.152 | 1.5.0.152 |
Apple TV | <1.5.0.152 | |
apple itunes windows | <12.13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44157 is a critical vulnerability due to its potential to cause unexpected system termination.
To fix CVE-2024-44157, update iTunes for Windows to version 12.13.3 or later and Apple TV for Windows to version 1.5.0.152 or later.
CVE-2024-44157 affects iTunes for Windows version up to 12.13.3 and Apple TV for Windows version up to 1.5.0.152.
CVE-2024-44157 is classified as a stack buffer overflow vulnerability.
CVE-2024-44157 can be exploited through maliciously crafted video files that are parsed by the affected software.