CVE-2008-2304

Apple Core Image Fun House < 2.0 - Buffer Overflow via String XML Element

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2304. PoCs published by Adriel T. Desautels.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Core Image Fun House by crafting a malicious XML file with an oversized string. The payload overwrites the return address to achieve arbitrary code execution.

Description

Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a .funhouse file with a string XML element that contains many characters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Adriel T. Desautels · rubydososx
https://www.exploit-db.com/exploits/6043

This exploit targets a buffer overflow vulnerability in Core Image Fun House by crafting a malicious XML file with an oversized string. The payload overwrites the return address to achieve arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Core Image Fun House (Apple)
No auth needed
Prerequisites: Victim must open the malicious .funhouse file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43733
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3988
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce//2008/Jul/msg00002.html
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6043
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT2352
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2093/references
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31060
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/494230/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30189
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020472

Scores

EPSS 0.0568
EPSS Percentile 92.0%

Details

CWE
CWE-119
Status published
Products (1)
apple/core_image_fun_house < 2.0
Published Jul 14, 2008
Tracked Since Feb 18, 2026