Apple iLife and Aperture Image Handling Code Execution Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Apple iLife and Aperture, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by uninitialized memory access and memory corruption errors in ImageIO when processing malformed LZW-encoded TIFF images or embedded ICC profiles in JPEG images, which could be exploited to crash an affected application or execute arbitrary code.
Impact
- Remote Code Execution
System / Technologies affected
- Apple iLife 8.0 on Mac OS versions 10.4.9 through 10.4.11
- Apple Aperture 2 on Mac OS versions 10.4.9 through 10.4.11
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply iLife Support 8.3.1 :
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=22080&cat=1&platform=osx&method=sa/iLifeSupport.dmg
Vulnerability Identifier
Source
Related Link
Share with