Skip to main content

Apple iLife and Aperture Image Handling Code Execution Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 12 Nov 2008 4738 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Apple iLife and Aperture, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by uninitialized memory access and memory corruption errors in ImageIO when processing malformed LZW-encoded TIFF images or embedded ICC profiles in JPEG images, which could be exploited to crash an affected application or execute arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • Apple iLife 8.0 on Mac OS versions 10.4.9 through 10.4.11
  • Apple Aperture 2 on Mac OS versions 10.4.9 through 10.4.11

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link