First published: Fri Apr 21 2006(Updated: )
Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit. NOTE: the BMP vector has been re-assigned to CVE-2006-2238 because it affects a separate product family.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.3 | |
Apple Mac OS X Server | =10.4.3 | |
Apple Mac OS X Server | =10.3.2 | |
Apple Mac OS X Server | =10.3.7 | |
Apple Mac OS X Server | =10.3.5 | |
macOS Yosemite | =10.3.1 | |
macOS Yosemite | =10.3.5 | |
macOS Yosemite | =10.4.1 | |
Apple Mac OS X Server | =10.4.2 | |
Apple Mac OS X Server | =10.3.3 | |
Apple Mac OS X Server | =10.4.4 | |
Apple Mac OS X Server | =10.4.1 | |
macOS Yosemite | =10.4.4 | |
Apple Mac OS X Server | =10.3.4 | |
macOS Yosemite | =10.3.2 | |
macOS Yosemite | =10.3.7 | |
Apple Mac OS X Server | =10.4 | |
Apple Mac OS X Server | =10.4.5 | |
macOS Yosemite | =10.3.6 | |
Apple Mac OS X Server | =10.3 | |
Apple Mac OS X Server | =10.3.8 | |
macOS Yosemite | =10.4 | |
Apple Mac OS X Server | =10.4.6 | |
Apple Mac OS X Server | =10.3.9 | |
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.3.8 | |
Apple Mac OS X Server | =10.3.1 | |
macOS Yosemite | =10.4.5 | |
macOS Yosemite | =10.3.9 | |
macOS Yosemite | =10.3.4 | |
macOS Yosemite | =10.3.3 | |
macOS Yosemite | =10.4.2 | |
macOS Yosemite | =10.3 | |
Apple Mac OS X Server | =10.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1983 is classified with a medium severity level due to its potential to cause denial of service and possible arbitrary code execution.
To fix CVE-2006-1983, update your Mac OS X to a version later than 10.4.6, as Apple released patches for this vulnerability.
CVE-2006-1983 affects Mac OS X versions 10.4.6 and earlier, as well as various earlier versions of Mac OS X Server.
CVE-2006-1983 may enable remote attackers to execute arbitrary code or cause a denial of service in affected applications using ImageIO or AppKit.
CVE-2006-1983 is less of a risk today due to the discontinuation of support for the affected versions, but users on those systems remain vulnerable.