Vulnerabilities > CVE-2007-1071 - Unspecified vulnerability in Apple mac OS X and mac OS X Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during decompression. NOTE: this is a different issue than CVE-2006-3502 and CVE-2006-3503.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 |
Exploit-Db
description | Apple Mac OS X 10.4.8 ImageIO GIF Image Integer Overflow Vulnerability. CVE-2007-1071. Dos exploit for osx platform |
id | EDB-ID:29620 |
last seen | 2016-02-03 |
modified | 2007-02-20 |
published | 2007-02-20 |
reporter | Tom Ferris |
source | https://www.exploit-db.com/download/29620/ |
title | Apple Mac OS X 10.4.8 - ImageIO GIF Image Integer Overflow Vulnerability |
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_10_4_9.NASL |
description | The remote host is running a version of Mac OS X 10.4 which is older than version 10.4.9 or a version of Mac OS X 10.3 which does not have Security Update 2007-003 applied. This update contains several security fixes for the following programs : - ColorSync - CoreGraphics - Crash Reporter - CUPS - Disk Images - DS Plugins - Flash Player - GNU Tar - HFS - HID Family - ImageIO - Kernel - MySQL server - Networking - OpenSSH - Printing - QuickDraw Manager - servermgrd - SMB File Server - Software Update - sudo - WebLog |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24811 |
published | 2007-03-13 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24811 |
title | Mac OS X < 10.4.9 Multiple Vulnerabilities (Security Update 2007-003) |
code |
|
References
- http://docs.info.apple.com/article.html?artnum=305214
- http://docs.info.apple.com/article.html?artnum=305214
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
- http://secunia.com/advisories/24479
- http://secunia.com/advisories/24479
- http://security-protocols.com/sp-x39-advisory.php
- http://security-protocols.com/sp-x39-advisory.php
- http://www.kb.cert.org/vuls/id/559444
- http://www.kb.cert.org/vuls/id/559444
- http://www.osvdb.org/34854
- http://www.osvdb.org/34854
- http://www.securityfocus.com/bid/22630
- http://www.securityfocus.com/bid/22630
- http://www.securitytracker.com/id?1017758
- http://www.securitytracker.com/id?1017758
- http://www.us-cert.gov/cas/techalerts/TA07-072A.html
- http://www.us-cert.gov/cas/techalerts/TA07-072A.html
- http://www.vupen.com/english/advisories/2007/0930
- http://www.vupen.com/english/advisories/2007/0930