CVE-2023-42867

This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
References
Link Resource
https://support.apple.com/en-us/120299 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apple:garageband:*:*:*:*:*:*:*:*

History

06 Jan 2025, 14:20

Type Values Removed Values Added
References () https://support.apple.com/en-us/120299 - () https://support.apple.com/en-us/120299 - Vendor Advisory
CPE cpe:2.3:a:apple:garageband:*:*:*:*:*:*:*:*
First Time Apple garageband
Apple
CWE NVD-CWE-noinfo

27 Dec 2024, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) Este problema se solucionó con una validación mejorada de la autorización del proceso y la identificación del equipo. Este problema se solucionó en GarageBand 10.4.9. Es posible que una aplicación pueda obtener privilegios de superusuario.
CWE CWE-281

20 Dec 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-20 04:15

Updated : 2025-01-06 14:20


NVD link : CVE-2023-42867

Mitre link : CVE-2023-42867

CVE.ORG link : CVE-2023-42867


JSON object : View

Products Affected

apple

  • garageband
CWE
NVD-CWE-noinfo CWE-281

Improper Preservation of Permissions