CVE-2007-3752

Description

Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
16.027

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Apple iTunes (X64) 7.3.2Windows
Multiple vulnerabilities affected in Apple iTunes 7.3.2Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 7.3.2Windows
Multiple Vulnerabilities are affected in Apple iTunes 7.3.2Windows
Vulnerabilities CVE-2007-3752 are affected in Apple iTunes For Mac 7.3.2--Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342817Apple iTunes (X64) (12.13.4.4)
PATCH-342816Apple iTunes (12.13.4.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234