Vulnerabilities > CVE-2008-1586 - Resource Management Errors vulnerability in Apple Iphone OS

047910
CVSS 7.1 - HIGH
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
apple
CWE-399
nessus

Summary

ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory consumption and device reset) via a crafted TIFF image.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_0_LIBTIFF-DEVEL-090205.NASL
    descriptionspecially crafted tiff images could lead to allocating large amounts of memory therefore crashing applications that process such files (CVE-2008-1586).
    last seen2020-06-01
    modified2020-06-02
    plugin id40049
    published2009-07-21
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/40049
    titleopenSUSE Security Update : libtiff-devel (libtiff-devel-507)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_1_LIBTIFF-DEVEL-090205.NASL
    descriptionspecially crafted tiff images could lead to allocating large amounts of memory therefore crashing applications that process such files (CVE-2008-1586).
    last seen2020-06-01
    modified2020-06-02
    plugin id40270
    published2009-07-21
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/40270
    titleopenSUSE Security Update : libtiff-devel (libtiff-devel-507)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_LIBTIFF-DEVEL-5988.NASL
    descriptionspecially crafted tiff images could lead to allocating large amounts of memory therefore crashing applications that process such files (CVE-2008-1586).
    last seen2020-06-01
    modified2020-06-02
    plugin id35678
    published2009-02-13
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/35678
    titleopenSUSE 10 Security Update : libtiff-devel (libtiff-devel-5988)

Statements

contributorJoshua Bressers
lastmodified2009-01-19
organizationRed Hat
statementRed Hat does not consider this libTIFF bug to be a security issue.