CVE-2010-0519
published 2010-03-30CVE-2010-0519: Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application…
PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
9.34%
94.9th percentile
Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wj8g-mf9j-qxgf: Integer overflow in QuickTime in Apple Mac OS X before 10
ghsa_unreviewed·2022-05-02
CVE-2010-0519 [MEDIUM] GHSA-wj8g-mf9j-qxgf: Integer overflow in QuickTime in Apple Mac OS X before 10
Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.
Red Hat
libtiff tiffdump integer overflow
vendor_redhat·2010-06-22·CVSS 4.3
CVE-2010-4665 [MEDIUM] CWE-190 libtiff tiffdump integer overflow
libtiff tiffdump integer overflow
Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.
Statement: This flaw has already been fixed in Red Hat Enterprise Linux 4 and 5 by a patch included in RHSA-2010:0519.
Package: libtiff (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
Bugzilla
CVE-2010-4665 libtiff tiffdump integer overflow
bugzilla·2011-04-12·CVSS 4.3
CVE-2010-4665 [MEDIUM] CVE-2010-4665 libtiff tiffdump integer overflow
CVE-2010-4665 libtiff tiffdump integer overflow
The libtiff utility tiffdump contains an integer overflow which can be
triggered when operating in a directory containing a large number of files.
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2218
Discussion:
Statement:
This flaw has already been fixed in Red Hat Enterprise Linux 4 and 5 by a patch included in RHSA-2010:0519.
---
Created libtiff tracking bugs for this issue
Affects: fedora-all [bug 696204]
---
So far as I can tell, this is not only not a security issue, it's not a bug at all. That fax2ps.c code is exactly the same upstream in 3.9.4 and 3.9.5 except for a gratuitous change in the spelling of the error message. It looks to me like the submitted patch was entirely reverted by Bob Friesenhahn per http://bu
Bugzilla
CVE-2010-2483 libtiff: out-of-bounds read crash on images with invalid SamplesPerPixel values
bugzilla·2010-07-06·CVSS 4.3
CVE-2010-2483 [MEDIUM] CVE-2010-2483 libtiff: out-of-bounds read crash on images with invalid SamplesPerPixel values
CVE-2010-2483 libtiff: out-of-bounds read crash on images with invalid SamplesPerPixel values
The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers
to cause a denial of service (out-of-bounds read and application
crash) via a TIFF file with an invalid combination of SamplesPerPixel
and Photometric values.
References:
https://bugs.launchpad.net/bugs/591605
https://bugzilla.redhat.com/show_bug.cgi?id=603081
http://bugzilla.maptools.org/show_bug.cgi?id=2216
http://secunia.com/advisories/40422
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0519 https://rhn.redhat.com/errata/RHSA-2010-0519.html
Bugzilla
CVE-2010-2481 libtiff: TIFFExtractData out-of-bounds read crash
bugzilla·2010-07-06·CVSS 4.3
CVE-2010-2481 [MEDIUM] CVE-2010-2481 libtiff: TIFFExtractData out-of-bounds read crash
CVE-2010-2481 libtiff: TIFFExtractData out-of-bounds read crash
The TIFFExtractData macro in LibTIFF before 3.9.4 does not properly
handle unknown tag types in TIFF directory entries, which allows
remote attackers to cause a denial of service (out-of-bounds read and
application crash) via a crafted TIFF file.
References:
http://thread.gmane.org/gmane.comp.security.oss.general/3075/focus=3097
http://bugzilla.maptools.org/show_bug.cgi?id=2210
Discussion:
According to Dan Rosenberg's report, this was originally reported to iDefense. Dan did not publish too much details about this issue, as it's addressed by Tom's patch from upstream bug report #2210.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0519 https:
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//Mar/msg00002.htmlhttp://support.apple.com/kb/HT4077http://www.securityfocus.com/archive/1/510519/100/0/threadedhttp://www.zerodayinitiative.com/advisories/ZDI-10-043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7498http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//Mar/msg00002.htmlhttp://support.apple.com/kb/HT4077http://www.securityfocus.com/archive/1/510519/100/0/threadedhttp://www.zerodayinitiative.com/advisories/ZDI-10-043https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7498
2010-03-30
Published