Description
Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".
References (9)
Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/17951
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1779
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/25597
Patch, Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-132A.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/17321
Patch vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2006/May/msg00003.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26412
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20077
Various Sources x_refsource_misc
http://drunkenblog.com/drunkenblog-archives/000760.html
Scores
EPSS
0.0436
EPSS Percentile
90.3%
Details
CWE
CWE-189
Status
published
Products (25)
apple/imageio
apple/mac_os_x
10.4
apple/mac_os_x
10.4.1
apple/mac_os_x
10.4.2
apple/mac_os_x
10.4.3
apple/mac_os_x
10.4.4
apple/mac_os_x
10.4.5
apple/mac_os_x_server
10.4
apple/mac_os_x_server
10.4.1
apple/mac_os_x_server
10.4.2
... and 15 more
Published
Mar 31, 2006
Tracked Since
Feb 18, 2026