Apple CoreGraphics Memory Corruption Error Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1020603
|
|
SecurityTracker URL: http://securitytracker.com/id?1020603
|
|
CVE Reference: CVE-2008-2321
(Links to External Site)
|
Date: Aug 1 2008
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Apple Security Advisory
|
Version(s): 10.4.11, 10.5.4
|
Description: A vulnerability was reported in Apple CoreGraphics. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted HTML that, when loaded by the target user, will trigger a memory corruption error in
CoreGraphics and execute arbitrary code on the target system.
Other applications that pass untrusted input to CoreGraphics may
be able to be used to exploit this.
Michal Zalewski of Google reported this vulnerability.
|
Impact: A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution: Apple has issued a fix (Security Update 2008-005), which can be downloaded and installed via Software Update preferences, or from
Apple Downloads at:
http://www.apple.com/support/downloads/
For Mac OS X v10.5.4 and Mac OS X Server 10.5.4
The download
file is named: "SecUpd2008-005.dmg"
Its SHA-1 digest is: 9c4fd4ee59965819427445f6de172c42b223e6e1
For Mac OS X v10.4.11 (Intel)
The
download file is named: "SecUpd2008-005Intel.dmg"
Its SHA-1 digest is: 1ff3242935c98325769b33148a2a8b1e72db567c
For Mac OS
X v10.4.11 (PPC)
The download file is named: "SecUpd2008-005PPC.dmg"
Its SHA-1 digest is: 2f56ea4311d5b85de3c494f6fee46360e5b7317e
For
Mac OS X Server v10.4.11 (Universal)
The download file is named: "SecUpdSrvr2008-005Univ.dmg"
Its SHA-1 digest is: 256401659308a634cee06b00d1a6ae9dc20b5467
For
Mac OS X Server v10.4.11 (PPC)
The download file is named: "SecUpdSrvr2008-005PPC.dmg"
Its SHA-1 digest is: d310d471bd39df92cb5580e18f356a222824d7d2
The
Apple advisory is available at:
http://support.apple.com/kb/HT2647
|
Vendor URL: support.apple.com/kb/HT2647 (Links to External Site)
|
Cause: Access control error
|
Underlying OS: UNIX (Mac OS X)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|