CVE-2016-4630
published 2016-07-22CVE-2016-4630: ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted EXR image…
PriorityP345high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
3.58%
88.2th percentile
ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted EXR image with B44 compression.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.11.5 | — |
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqpv-jpx8-946m: ImageIO in Apple OS X before 10
ghsa_unreviewed·2022-05-17
CVE-2016-4630 [HIGH] CWE-119 GHSA-gqpv-jpx8-946m: ImageIO in Apple OS X before 10
ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted EXR image with B44 compression.
Apple
CVE-2016-4630: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 8.8
CVE-2016-4630 [HIGH] CVE-2016-4630: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-4630
Component: ImageIO
Impact: A remote attacker may be able to execute arbitrary code
Description: Multiple memory corruption issues were addressed through improved memory handling.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Apple Remote Code Execution With Image Files
blogs_talos·2016-07-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Apple Remote Code Execution With Image Files
Vulnerabilities discovered by Tyler Bohan of Cisco Talos.
Many of the wide variety of file formats are designed for specialized uses within specific industries. Apple offers APIs as interfaces to provide a definitive way to access image data for multiple image formats on the Apple OS X platform. Talos is disclosing the presence of five remote code execution vulnerabilities in Apple OS X related to processing image formats: TALOS-2016-0171, TALOS-2016-0180,TALOS-2016-0181, TALOS-2016-0183, TALOS-2016-186.
## TALOS-2016-0171
### Tagged Image File Format (TIFF) (CVE-2016-4631)
The Tagged Image File Format (TIFF) is a file format that is popular with graphic artists, photographers and the publishing industry because of its ability to store images in a lossless format. TIFF was created to t
Talos
Vulnerability Spotlight: Apple Remote Code Execution With Image Files
blogs_talos·2016-07-19·CVSS 8.8
[HIGH] Vulnerability Spotlight: Apple Remote Code Execution With Image Files
## Vulnerability Spotlight: Apple Remote Code Execution With Image Files
Vulnerabilities discovered by Tyler Bohan of Cisco Talos.
Many of the wide variety of file formats are designed for specialized uses within specific industries. Apple offers APIs as interfaces to provide a definitive way to access image data for multiple image formats on the Apple OS X platform. Talos is disclosing the presence of five remote code execution vulnerabilities in Apple OS X related to processing image formats: TALOS-2016-0171, TALOS-2016-0180,TALOS-2016-0181, TALOS-2016-0183, TALOS-2016-186.
## TALOS-2016-0171
## Tagged Image File Format (TIFF) (CVE-2016-4631)
The Tagged Image File Format (TIFF) is a file format that is popular with graphic artists, photographers and the publishing industry because o
Bugzilla
CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
bugzilla·2016-11-22·CVSS 6.5
CVE-2016-8734 [MEDIUM] CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
CVE-2016-8734 subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s)://
It was discovered that Subversion's mod_dontdothat module and Subversion clients using http(s):// are vulnerable to a denial-of-service attack caused by exponential XML entity expansion.
An authenticated remote attacker can cause denial-of-service conditions on the server using mod_dontdothat by sending a specially crafted REPORT request. The attack does not require access to a particular repository.
If an attacker has control over HTTP responses sent to a Subversion client, they can cause denial-of-service conditions on the client by injecting an XML bomb into the response.
Upstream bug:
https://issues.apache.org/jira/browse/SVN-4630
Discussion:
Acknowledgments:
Na
http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://www.securityfocus.com/bid/91824http://www.securitytracker.com/id/1036348http://www.talosintelligence.com/reports/TALOS-2016-0181/https://github.com/openexr/openexr/issues/563https://support.apple.com/HT206903http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://www.securityfocus.com/bid/91824http://www.securitytracker.com/id/1036348http://www.talosintelligence.com/reports/TALOS-2016-0181/https://github.com/openexr/openexr/issues/563https://support.apple.com/HT206903
2016-07-22
Published