A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Dec 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple apple Tv
Apple itunes
Weaknesses CWE-787
CPEs cpe:2.3:a:apple:apple_tv:*:*:*:*:*:windows:*:*
cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*
Vendors & Products Apple
Apple apple Tv
Apple itunes

Sun, 27 Oct 2024 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Tue, 15 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
Description A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2024-10-27T01:45:07.331Z

Reserved: 2024-08-20T21:42:05.924Z

Link: CVE-2024-44157

cve-icon Vulnrichment

Updated: 2024-10-15T18:21:39.267Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-11T18:15:08.030

Modified: 2024-12-12T19:09:01.313

Link: CVE-2024-44157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.