SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   OS (UNIX)  >   Apple CoreGraphics Vendors:   Apple
Apple CoreGraphics Memory Corruption Error Lets Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1020603
SecurityTracker URL:  http://securitytracker.com/id/1020603
CVE Reference:   CVE-2008-2321   (Links to External Site)
Date:  Aug 1 2008
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 10.4.11, 10.5.4
Description:   A vulnerability was reported in Apple CoreGraphics. A remote user can cause arbitrary code to be executed on the target user's system.

A remote user can create a specially crafted HTML that, when loaded by the target user, will trigger a memory corruption error in CoreGraphics and execute arbitrary code on the target system.

Other applications that pass untrusted input to CoreGraphics may be able to be used to exploit this.

Michal Zalewski of Google reported this vulnerability.

Impact:   A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution:   Apple has issued a fix (Security Update 2008-005), which can be downloaded and installed via Software Update preferences, or from Apple Downloads at:

http://www.apple.com/support/downloads/

For Mac OS X v10.5.4 and Mac OS X Server 10.5.4
The download file is named: "SecUpd2008-005.dmg"
Its SHA-1 digest is: 9c4fd4ee59965819427445f6de172c42b223e6e1

For Mac OS X v10.4.11 (Intel)
The download file is named: "SecUpd2008-005Intel.dmg"
Its SHA-1 digest is: 1ff3242935c98325769b33148a2a8b1e72db567c

For Mac OS X v10.4.11 (PPC)
The download file is named: "SecUpd2008-005PPC.dmg"
Its SHA-1 digest is: 2f56ea4311d5b85de3c494f6fee46360e5b7317e

For Mac OS X Server v10.4.11 (Universal)
The download file is named: "SecUpdSrvr2008-005Univ.dmg"
Its SHA-1 digest is: 256401659308a634cee06b00d1a6ae9dc20b5467

For Mac OS X Server v10.4.11 (PPC)
The download file is named: "SecUpdSrvr2008-005PPC.dmg"
Its SHA-1 digest is: d310d471bd39df92cb5580e18f356a222824d7d2

The Apple advisory is available at:

http://support.apple.com/kb/HT2647

Vendor URL:  support.apple.com/kb/HT2647 (Links to External Site)
Cause:   Access control error

Message History:   This archive entry has one or more follow-up message(s) listed below.
Nov 21 2008 (Apple Issues Fix for iPhone) Apple CoreGraphics Memory Corruption Error Lets Remote Users Execute Arbitrary Code
Apple has issued a fix for iPhone.



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2020, SecurityGlobal.net LLC