ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html | vendor advisory |
http://www.securityfocus.com/bid/38676 | vdb entry patch |
http://support.apple.com/kb/HT4225 | |
http://www.securitytracker.com/id?1023706 | vdb entry |
http://secunia.com/advisories/39135 | third party advisory |
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6885 | vdb entry signature |
http://support.apple.com/kb/HT4105 | |
http://support.apple.com/kb/HT4070 | vendor advisory |
http://support.apple.com/kb/HT4077 | |
http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html | vendor advisory |
http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html | vendor advisory |
http://www.securityfocus.com/bid/38671 | vdb entry patch |