2025-01-30 21:03:56 +00:00
{
"id" : "CVE-2024-44142" ,
"sourceIdentifier" : "product-security@apple.com" ,
"published" : "2025-01-30T19:15:13.910" ,
2025-03-18 17:03:48 +00:00
"lastModified" : "2025-03-18T16:06:18.150" ,
"vulnStatus" : "Analyzed" ,
2025-01-30 21:03:56 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution."
2025-01-31 21:03:47 +00:00
} ,
{
"lang" : "es" ,
"value" : "El problema se solucion\u00f3 con comprobaciones de los l\u00edmites mejoradas. Este problema se solucion\u00f3 en GarageBand 10.4.12. El procesamiento de una imagen manipulado malintencionada puede provocar la ejecuci\u00f3n de c\u00f3digo arbitrario."
2025-01-30 21:03:56 +00:00
}
] ,
2025-01-31 21:03:47 +00:00
"metrics" : {
"cvssMetricV31" : [
2025-03-18 17:03:48 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
} ,
2025-01-31 21:03:47 +00:00
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
}
]
} ,
2025-03-18 17:03:48 +00:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:apple:garageband:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "10.4.12" ,
"matchCriteriaId" : "08180A03-77F4-4F8B-98F7-8A38A931127E"
}
]
}
]
}
] ,
2025-01-30 21:03:56 +00:00
"references" : [
{
"url" : "https://support.apple.com/en-us/121866" ,
2025-03-18 17:03:48 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Vendor Advisory" ,
"Release Notes"
]
2025-02-02 11:03:48 +00:00
} ,
{
"url" : "http://seclists.org/fulldisclosure/2025/Feb/2" ,
2025-03-18 17:03:48 +00:00
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory" ,
"Release Notes"
]
2025-01-30 21:03:56 +00:00
}
]
}