Apple Mac OS X ImageIO OpenEXR Image File Remote Denial Of Service Vulnerability
BID:17768
Info
Apple Mac OS X ImageIO OpenEXR Image File Remote Denial Of Service Vulnerability
| Bugtraq ID: | 17768 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-2277 |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Discovery of this issue is credited to Christian <[email protected]>. |
| Vulnerable: |
Apple Safari RSS 2.0 pre-release Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari 1.3 Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 Apple Safari Beta 2 Apple Mobile Safari 0 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X ImageIO OpenEXR Image File Remote Denial Of Service Vulnerability
ImageIO is susceptible to a remote denial-of-service vulnerability. This issue is do to a failure to properly process malicious OpenEXR image files.
This issue allows remote users to crash applications that use the ImageIO API, denying further service to users.
ImageIO is susceptible to a remote denial-of-service vulnerability. This issue is do to a failure to properly process malicious OpenEXR image files.
This issue allows remote users to crash applications that use the ImageIO API, denying further service to users.
Exploit / POC
Apple Mac OS X ImageIO OpenEXR Image File Remote Denial Of Service Vulnerability
The following OpenEXR file is sufficient to demonstrate this issue:
The following OpenEXR file is sufficient to demonstrate this issue:
Solution / Fix
Apple Mac OS X ImageIO OpenEXR Image File Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Apple Mac OS X ImageIO OpenEXR Image File Remote Denial Of Service Vulnerability
References:
References:
- Mac OS X Homepage (Apple)
- OpenEXR Home Page (OpenEXR)
- Safari Homepage (Apple)
- Image file crashes Finder, Safari and other apps ([email protected])