First published: Fri Jun 24 2011(Updated: )
Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.5.8 | |
macOS Yosemite | =10.6.7 | |
macOS Yosemite | =10.6.3 | |
Apple ImageIO | ||
macOS Yosemite | =10.6.6 | |
macOS Yosemite | =10.6.1 | |
macOS Yosemite | =10.6.0 | |
macOS Yosemite | =10.6.2 | |
macOS Yosemite | =10.6.4 | |
macOS Yosemite | =10.6.5 | |
Apple Mac OS X Server | =10.5.8 | |
Apple Mac OS X Server | =10.6.3 | |
Apple Mac OS X Server | =10.6.6 | |
Apple Mac OS X Server | =10.6.4 | |
Apple Mac OS X Server | =10.6.7 | |
Apple Mac OS X Server | =10.6.5 | |
Apple Mac OS X Server | =10.6.1 | |
Apple Mac OS X Server | =10.6.2 | |
Apple Mac OS X Server | =10.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0205 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2011-0205, users should update to Mac OS X versions 10.6.8 or later, as these versions include the necessary security patches.
CVE-2011-0205 affects Apple Mac OS X versions 10.5.8 and 10.6.x prior to 10.6.8.
CVE-2011-0205 enables attackers to execute arbitrary code or cause denial of service through specially crafted JPEG2000 images.
Yes, opening JPEG2000 images on vulnerable systems can lead to application crashes or arbitrary code execution.