Apple Safari ImageIO TIFF Image Remote Code Execution Vulnerability
BID:38673
Info
Apple Safari ImageIO TIFF Image Remote Code Execution Vulnerability
| Bugtraq ID: | 38673 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-0043 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2010 12:00AM |
| Updated: | Jun 21 2010 10:28PM |
| Credit: | Gus Mueller of Flying Meat |
| Vulnerable: |
Apple Safari 4.0.4 for Windows Apple Safari 4.0.3 for Windows Apple Safari 4.0.2 for Windows Apple Safari 4 for Windows Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.5.8 Apple Mac OS X 10.6 Apple iTunes 9.0.2 Apple iTunes 9.0.1 .8 Apple iTunes 9.0.1 Apple iTunes 9.0 Apple iTunes 8.2 Apple iTunes 8.1 Apple iTunes 8.0.2.20 Apple iTunes 8.0 Apple iPod Touch 3.1.3 Apple iPod Touch 3.1.2 Apple iPod Touch 3.1.1 Apple iPod Touch 2.2.1 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 3.0 Apple iPod Touch 2.2 Apple iPod Touch 2.1 Apple iPod Touch 2.0 Apple iPhone 3.1.3 Apple iPhone 3.1.2 Apple iPhone 3.0.1 Apple iPhone 2.2.1 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 3.1 Apple iPhone 3.0 Apple iPhone 2.2 Apple iPhone 2.1 Apple iPhone 2.0 |
| Not Vulnerable: |
Apple Safari 4.0.5 for Windows Apple Mac OS X Server 10.6.3 Apple Mac OS X 10.6.3 Apple iTunes 9.1 Apple iOS 4 |
Discussion
Apple Safari ImageIO TIFF Image Remote Code Execution Vulnerability
Safari is prone to a remote code-execution vulnerability because it fails to properly handle crafted TIFF images.
Attackers may exploit this issue to execute arbitrary code in the context of the application. Failed attacks will result in a denial-of-service condition.
Versions prior to Safari 4.0.5 running on Microsoft Windows 7, XP, and Vista are vulnerable.
This issue was previously documented in BID 38671 (Apple Safari Prior to 4.0.5 Multiple Security Vulnerabilities) but has been given its own record to better document it.
Safari is prone to a remote code-execution vulnerability because it fails to properly handle crafted TIFF images.
Attackers may exploit this issue to execute arbitrary code in the context of the application. Failed attacks will result in a denial-of-service condition.
Versions prior to Safari 4.0.5 running on Microsoft Windows 7, XP, and Vista are vulnerable.
This issue was previously documented in BID 38671 (Apple Safari Prior to 4.0.5 Multiple Security Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
Apple Safari ImageIO TIFF Image Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple Safari ImageIO TIFF Image Remote Code Execution Vulnerability
Solution:
Vendor fixes are available. Please see the referenced advisory for details.
Apple Safari 4 for Windows
Apple Mac OS X Server 10.6
Apple Mac OS X 10.6
Apple Mac OS X Server 10.5.8
Apple Mac OS X 10.5.8
Apple Mac OS X 10.6.1
Apple Mac OS X Server 10.6.1
Apple Mac OS X Server 10.6.2
Apple Mac OS X 10.6.2
Apple Safari 4.0.2 for Windows
Apple Safari 4.0.3 for Windows
Apple Safari 4.0.4 for Windows
Apple iTunes 9.0.2
Solution:
Vendor fixes are available. Please see the referenced advisory for details.
Apple Safari 4 for Windows
-
Apple APPLE-SA-2010-03-11-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2010-03-11-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2010-03-11-1-SafariQuickTimeSetup.exe
Safari+QuickTime for Windows 7, Vista or XP
http://www.apple.com/safari/download/
Apple Mac OS X Server 10.6
-
Apple MacOSXServerUpdCombo10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6
-
Apple MacOSXUpdCombo10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.5.8
-
Apple SecUpdSrvr2010-002Leo.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.5.8
-
Apple SecUpd2010-002Leo.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.1
-
Apple MacOSXUpdCombo10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.1
-
Apple MacOSXServerUpdCombo10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.2
-
Apple MacOSXServerUpd10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.2
-
Apple MacOSXUpd10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Safari 4.0.2 for Windows
-
Apple APPLE-SA-2010-03-11-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2010-03-11-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2010-03-11-1-SafariQuickTimeSetup.exe
Safari+QuickTime for Windows 7, Vista or XP
http://www.apple.com/safari/download/
Apple Safari 4.0.3 for Windows
-
Apple APPLE-SA-2010-03-11-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2010-03-11-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2010-03-11-1-SafariQuickTimeSetup.exe
Safari+QuickTime for Windows 7, Vista or XP
http://www.apple.com/safari/download/
Apple Safari 4.0.4 for Windows
-
Apple APPLE-SA-2010-03-11-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2010-03-11-1-Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2010-03-11-1-SafariQuickTimeSetup.exe
Safari+QuickTime for Windows 7, Vista or XP
http://www.apple.com/safari/download/
Apple iTunes 9.0.2
-
Apple APPLE-SA-2010-03-30-2iTunes64Setup.exe
For 64-bit Windows XP / Vista / Windows 7
http://www.apple.com/itunes/download/ -
Apple APPLE-SA-2010-03-30-2iTunesSetup.exe
For Windows XP / Vista / Windows 7
http://www.apple.com/itunes/download/
References
Apple Safari ImageIO TIFF Image Remote Code Execution Vulnerability
References:
References:
- Apple Safari Homepage (Apple)