CVE-2010-0036: Buffer Overflow
Published Jan 20, 2010
·Updated
Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.
Affected Software
4 affected components
Apple iOS and macOS=10.5.8
Apple Mac OS X Server=10.5.8
Apple Mac OS X Server=10.6.2
Apple iOS and macOS=10.6.2
Remediation
Patch Available
Event History
Jan 20, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0036?
CVE-2010-0036 has a severity level of high due to its potential for allowing remote code execution.
2
How do I fix CVE-2010-0036?
To address CVE-2010-0036, you should update to the latest version of Mac OS X that is not vulnerable to this issue.
3
What platforms are affected by CVE-2010-0036?
CVE-2010-0036 affects Apple Mac OS X versions 10.5.8 and 10.6.2, as well as their server counterparts.
4
What type of attack does CVE-2010-0036 allow?
CVE-2010-0036 allows remote attackers to execute arbitrary code or cause a denial of service through a crafted MP4 audio file.
5
Is CVE-2010-0036 still a risk for users?
CVE-2010-0036 remains a risk for users who have not upgraded from the vulnerable versions of Mac OS X.