Description
A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.
References (2)
Core 2
Core References
Vendor Advisory
https://support.apple.com/en-us/121328
Vendor Advisory
https://support.apple.com/en-us/121441
Scores
CVSS v3
5.5
EPSS
0.0008
EPSS Percentile
22.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-120
CWE-787
Status
published
Products (4)
Apple/Apple TV
< 1.5.0
apple/apple_tv
< 1.5.0.152
apple/itunes
< 12.13.3
Apple/iTunes for Windows
< 12.13.3
Published
Oct 11, 2024
Tracked Since
Feb 18, 2026