First published: Mon Jun 02 2008(Updated: )
The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.4.11 | |
macOS Yosemite | <=10.5.2 | |
macOS Yosemite | =10.5.1 | |
Apple Mac OS X Server | =10.5.1 | |
macOS Yosemite | =10.5 | |
Apple Mac OS X Server | <=10.5.2 | |
macOS Yosemite | =10.4.11 | |
Apple Mac OS X Server | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1573 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2008-1573, update your Apple Mac OS X to version 10.5.3 or later.
CVE-2008-1573 affects Apple Mac OS X versions prior to 10.5.3 and includes both client and server variants.
CVE-2008-1573 allows attackers to conduct crafted image attacks that lead to out-of-bounds reading, potentially exposing memory contents.
Yes, CVE-2008-1573 can be exploited remotely via specially crafted BMP or GIF images.