Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-2332

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2008-2332
Last Modified 30 Oct 2012 10:57:23
Published 16 Sep 2008 07:00:01
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-2332

Summary

ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.

Vulnerable Systems

Operating System

  • Apple Mac Os X 10.4.11

  • Apple Mac Os X 10.5

  • Apple Mac Os X 10.5.1

  • Apple Mac Os X 10.5.2

  • Apple Mac Os X 10.5.3

  • Apple Mac Os X 10.5.4

  • Apple Mac Os X Server 10.4.11

  • Apple Mac Os X Server 10.5

  • Apple Mac Os X Server 10.5.1

  • Apple Mac Os X Server 10.5.2

  • Apple Mac Os X Server 10.5.3

  • Apple Mac Os X Server 10.5.4


References

CERT - TA08-260A

BID - 31189

XF - macos-tiff-code-execution(45167)

VUPEN - ADV-2008-3107

VUPEN - ADV-2008-2584

SECTRACK - 1020876

CONFIRM - http://support.apple.com/kb/HT3298

CONFIRM - http://support.apple.com/kb/HT3276

SECUNIA - 31882

APPLE - APPLE-SA-2008-09-15

APPLE - APPLE-SA-2008-11-13

SECUNIA - 32706

Related Patches

Apple 2008-09-15 Security Update 2008-006 (PPC)

Apple 2008-09-15 Security Update 2008-006 Server (PPC)

Apple 2008-09-15 Mac OS X 10.5.5 Update

Apple 2008-09-15 Mac OS X Server 10.5.5 Combo Update

Apple 2008-09-15 Mac OS X Server 10.5.5 Update

Apple 2008-09-15 Security Update 2008-006 (Intel)

Apple 2008-09-15 Mac OS X 10.5.5 Combo Update

Apple 2008-09-15 Security Update 2008-006 Server (Intel)

Apple 2008-11-10 iLife Support 8.3.1 for Tiger


Last Updated: 27 May 2016 10:55:04