CVE-2006-1982: Buffer Overflow
Published Apr 21, 2006
·Updated
Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.
Affected Software
32 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.3.2
Apple Mac OS X Server=10.3.7
Apple Mac OS X Server=10.3.5
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.3.4
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.7
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.5
Apple iOS and macOS=10.3.6
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.3.8
Apple iOS and macOS=10.4
Apple Mac OS X Server=10.3.9
Apple iOS and macOS=10.3.8
Apple Mac OS X Server=10.3.1
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.3
Apple Mac OS X Server=10.3.6
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Apr 21, 2006
CVE Published
10:02 PM
Apr 22, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1982?
CVE-2006-1982 is classified as a high severity vulnerability due to its potential to allow remote code execution through crafted TIFF images.
2
How do I fix CVE-2006-1982?
To mitigate CVE-2006-1982, users should update their Mac OS X software to version 10.4.6 or later.
3
What types of applications are affected by CVE-2006-1982?
CVE-2006-1982 affects applications that utilize ImageIO or AppKit in Mac OS X.
4
Can CVE-2006-1982 be exploited remotely?
Yes, CVE-2006-1982 can be exploited remotely by attackers through the use of specially crafted TIFF images.
5
What versions of Mac OS X are impacted by CVE-2006-1982?
CVE-2006-1982 impacts various versions of Mac OS X prior to 10.4.6, including 10.4.3 and earlier.