CVE-2008-1574Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple MAC OS X

Severity
9.3CRITICALNVD
EPSS
5.6%
top 9.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateMay 1

Description

Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffer overflow.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDapple/mac_os_x4 versions+3
NVDapple/mac_os_x_server4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jhg3-999m-vxmh: Integer overflow in ImageIO in Apple Mac OS X before 102022-05-01
CVEList
CVE-2008-1574: Integer overflow in ImageIO in Apple Mac OS X before 102008-06-02
CVE-2008-1574 — Apple MAC OS X vulnerability | cvebase