CVE-2009-1726: Buffer Overflow
Published Aug 6, 2009
·Updated
Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.
Affected Software
22 affected components
Apple iOS and macOS=10.5.2-2008-002
Apple Mac OS X Server=10.5.2
Apple iOS and macOS=10.5.6
Apple Mac OS X Server=10.4.11
Apple iOS and macOS=10.5.5
Apple Mac OS X Server=10.5.5
Apple iOS and macOS=10.5.1
Apple Mac OS X Server=10.5.1
Apple Mac OS X Server=10.5.6
Apple iOS and macOS=10.5.3
Apple iOS and macOS=10.5.0
Apple Mac OS X Server=10.5.0
Apple Mac OS X Server=10.5.3
Apple iOS and macOS=10.5
Apple Mac OS X Server=10.5.4
Apple iOS and macOS=10.5.2
Apple Mac OS X Server=10.5.7
Apple iOS and macOS=10.5.6
Apple iOS and macOS=10.5.7
Apple iOS and macOS=10.4.11
Apple Mac OS X Server=10.5
Apple iOS and macOS=10.5.4
Remediation
Patch Available
Patch Available
Event History
Aug 6, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1726?
CVE-2009-1726 is considered critical due to its potential for remote code execution and application crashes.
2
How do I fix CVE-2009-1726?
To fix CVE-2009-1726, upgrade to Mac OS X 10.5.8 or later where the vulnerability has been patched.
3
What kind of attack is possible with CVE-2009-1726?
CVE-2009-1726 allows remote attackers to execute arbitrary code or cause a denial of service through specially crafted images.
4
Which versions of Mac OS X are affected by CVE-2009-1726?
CVE-2009-1726 affects Apple Mac OS X 10.4.11 and all versions of 10.5 before 10.5.8.
5
Is the CVE-2009-1726 vulnerability specific to certain applications?
CVE-2009-1726 specifically impacts the ColorSync component in Mac OS X.