CVE-2016-4629
published 2016-07-22CVE-2016-4629: ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted xStride and…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
7.42%
93.8th percentile
ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted xStride and yStride values in an EXR image.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.5 | — |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-65m9-xc97-mrf6: ImageIO in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2016-4629 [CRITICAL] CWE-119 GHSA-65m9-xc97-mrf6: ImageIO in Apple OS X before 10
ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted xStride and yStride values in an EXR image.
Apple
CVE-2016-4629: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 9.8
CVE-2016-4629 [CRITICAL] CVE-2016-4629: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-4629
Component: ImageIO
Impact: A remote attacker may be able to execute arbitrary code
Description: Multiple memory corruption issues were addressed through improved memory handling.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Apple Remote Code Execution With Image Files
blogs_talos·2016-07-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Apple Remote Code Execution With Image Files
Vulnerabilities discovered by Tyler Bohan of Cisco Talos.
Many of the wide variety of file formats are designed for specialized uses within specific industries. Apple offers APIs as interfaces to provide a definitive way to access image data for multiple image formats on the Apple OS X platform. Talos is disclosing the presence of five remote code execution vulnerabilities in Apple OS X related to processing image formats: TALOS-2016-0171, TALOS-2016-0180,TALOS-2016-0181, TALOS-2016-0183, TALOS-2016-186.
## TALOS-2016-0171
### Tagged Image File Format (TIFF) (CVE-2016-4631)
The Tagged Image File Format (TIFF) is a file format that is popular with graphic artists, photographers and the publishing industry because of its ability to store images in a lossless format. TIFF was created to t
Talos
Vulnerability Spotlight: Apple Remote Code Execution With Image Files
blogs_talos·2016-07-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Apple Remote Code Execution With Image Files
## Vulnerability Spotlight: Apple Remote Code Execution With Image Files
Vulnerabilities discovered by Tyler Bohan of Cisco Talos.
Many of the wide variety of file formats are designed for specialized uses within specific industries. Apple offers APIs as interfaces to provide a definitive way to access image data for multiple image formats on the Apple OS X platform. Talos is disclosing the presence of five remote code execution vulnerabilities in Apple OS X related to processing image formats: TALOS-2016-0171, TALOS-2016-0180,TALOS-2016-0181, TALOS-2016-0183, TALOS-2016-186.
## TALOS-2016-0171
## Tagged Image File Format (TIFF) (CVE-2016-4631)
The Tagged Image File Format (TIFF) is a file format that is popular with graphic artists, photographers and the publishing industry because o
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://www.securityfocus.com/bid/91824http://www.securitytracker.com/id/1036348http://www.talosintelligence.com/reports/TALOS-2016-0180/https://github.com/openexr/openexr/issues/563https://support.apple.com/HT206903http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://www.securityfocus.com/bid/91824http://www.securitytracker.com/id/1036348http://www.talosintelligence.com/reports/TALOS-2016-0180/https://github.com/openexr/openexr/issues/563https://support.apple.com/HT206903
2016-07-22
Published