PT-2006-3243 · Apple+1 · Preview+4
Cary-Ilm
·
Published
2006-05-09
·
Updated
2018-10-18
·
CVE-2006-2277
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X version 10.4
Description
The issue allows context-dependent attackers to cause a denial of service, resulting in an application crash, by using a crafted OpenEXR (.exr) image file. This crash can occur when opening a folder using Finder, displaying the image in Safari, or using Preview to open the file.
Recommendations
For Apple Mac OS X version 10.4, consider avoiding the use of OpenEXR (.exr) image files until a fix is available. As a temporary workaround, restrict the use of applications that can open these files, such as Preview, to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Finder
Macos X
Openexr
Preview
Safari