CVE-2010-0042
Summary
| CVE | CVE-2010-0042 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-15 13:28:25 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Safari | 4.0 | All | All | All |
| Application | Apple | Safari | 4.0.0b | All | All | All |
| Application | Apple | Safari | 4.0.1 | All | All | All |
| Application | Apple | Safari | 4.0.2 | All | All | All |
| Application | Apple | Safari | 4.0.3 | All | All | All |
| Application | Apple | Safari | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple iTunes Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About the security content of iOS 4.2 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| APPLE-SA-2010-03-30-2 iTunes 9.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of iTunes 9.1 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| APPLE-SA-2010-11-22-1 iOS 4.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of iOS 4 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Apple iOS Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| APPLE-SA-2010-06-21-1 iOS 4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| About the security content of Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| SecurityTracker.com Archives - Apple Safari Bugs Let Remote Users Cause Arbitrary Code to Be Executed | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| About the security content of Safari 4.0.5 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| RETIRED: Apple Safari Prior to 4.0.5 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Apple Safari TIFF Image Uninitialized Memory Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| APPLE-SA-2010-03-11-1 Safari 4.0.5 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.