CVE-2023-42867
HIGHDescription
This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
Is your site exposed to CVE-2023-42867?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| apple | garageband |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2023-42867? +
How severe is CVE-2023-42867? +
What products are affected by CVE-2023-42867? +
How do I check if I'm vulnerable to CVE-2023-42867? +
Related Vulnerabilities
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and …
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of …
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content …
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via …
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When …
A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and …