>> Apple iLife and Aperture Image Handling Code Execution Vulnerabilities
Title : Apple iLife and Aperture Image Handling Code Execution Vulnerabilities VUPEN ID : VUPEN/ADV-2008-3107 CVE ID : CVE-2008-2327 - CVE-2008-2332 - CVE-2008-3608 CWE ID : CWE-119
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-11-11
Technical Description
Multiple vulnerabilities have been identified in Apple iLife and Aperture, which could be exploited by remote attackers to compromise a vulnerable system. These issues are caused by uninitialized memory access and memory corruption errors in ImageIO when processing malformed LZW-encoded TIFF images or embedded ICC profiles in JPEG images, which could be exploited to crash an affected application or execute arbitrary code.