CVE-2008-1573Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple MAC OS X

Severity
7.1HIGHNVD
EPSS
0.8%
top 26.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateMay 1

Description

The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read.

CVSS vector

AV:N/AC:M/C:C/I:N/A:NExploitability: 8.6 | Impact: 6.9

Affected Packages2 packages

NVDapple/mac_os_x10.5.2+3
NVDapple/mac_os_x_server10.5.2+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j8r3-8vrj-j6x6: The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 102022-05-01
CVEList
CVE-2008-1573: The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 102008-06-02
CVE-2008-1573 — Apple MAC OS X vulnerability | cvebase