2024-12-20 05:03:45 +00:00
{
"id" : "CVE-2023-42867" ,
"sourceIdentifier" : "product-security@apple.com" ,
"published" : "2024-12-20T04:15:05.200" ,
2025-01-06 15:03:44 +00:00
"lastModified" : "2025-01-06T14:20:04.917" ,
"vulnStatus" : "Analyzed" ,
2024-12-20 05:03:45 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges."
2024-12-27 21:03:40 +00:00
} ,
{
"lang" : "es" ,
"value" : "Este problema se solucion\u00f3 con una validaci\u00f3n mejorada de la autorizaci\u00f3n del proceso y la identificaci\u00f3n del equipo. Este problema se solucion\u00f3 en GarageBand 10.4.9. Es posible que una aplicaci\u00f3n pueda obtener privilegios de superusuario."
}
] ,
"metrics" : {
"cvssMetricV31" : [
2025-01-06 15:03:44 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
} ,
2024-12-27 21:03:40 +00:00
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
2025-01-06 15:03:44 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
} ,
2024-12-27 21:03:40 +00:00
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-281"
}
]
2024-12-20 05:03:45 +00:00
}
] ,
2025-01-06 15:03:44 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:apple:garageband:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "10.4.9" ,
"matchCriteriaId" : "78ED0789-F3CD-4105-A3FA-3DBE0705A9F9"
}
]
}
]
}
] ,
2024-12-20 05:03:45 +00:00
"references" : [
{
"url" : "https://support.apple.com/en-us/120299" ,
2025-01-06 15:03:44 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-20 05:03:45 +00:00
}
]
}