CVE-2006-2277: Medium severity Apple iOS and macOS vulnerability
Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash when opening a folder using Finder, displaying the image in Safari, or using Preview to open the file.
Affected Software
Event History
Frequently Asked Questions
Which user actions can trigger the crash?
The crash can be triggered when Finder opens a folder containing a crafted OpenEXR (.exr) image, when Safari displays the image, or when Preview opens the file.
What does an attacker need to exploit this issue?
An attacker needs to provide a crafted OpenEXR (.exr) image and have it processed by an affected application. The listed vector indicates network reachability, low attack complexity, and no authentication requirement.
What is the known impact?
The reported impact is denial of service through an application crash. No confidentiality or integrity impact is listed.