CVE-2023-42867

This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
References
Link Resource
https://support.apple.com/en-us/120299 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apple:garageband:*:*:*:*:*:*:*:*

History

06 Jan 2025, 14:20

Type Values Removed Values Added
First Time Apple
Apple garageband
CPE cpe:2.3:a:apple:garageband:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/120299 - () https://support.apple.com/en-us/120299 - Vendor Advisory
CWE NVD-CWE-noinfo

27 Dec 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-20 04:15

Updated : 2025-01-06 14:20


NVD link : CVE-2023-42867

Mitre link : CVE-2023-42867

CVE.ORG link : CVE-2023-42867


JSON object : View

Products Affected

apple

  • garageband
CWE
NVD-CWE-noinfo CWE-281

Improper Preservation of Permissions