Apple OS X ImageIO ‘gifGetBandProc’ Integer Overflow

From the advisory:

An integer overflow vulnerability exists within ImageIO when processing a malformed .gif file. This allows for an attacker to cause the application to crash, and or to execute arbitrary code on the targeted host.

Below is a link to the advisory:

Apple OS X ImageIO “gifGetBandProc” Integer Overflow

3 Comments »

  1. Bert JW Regeer Said,

    February 20, 2007 @ 2:03 am

    Damnit, accidently clicked on the image file causing Safari to take a dump :P. O well.

    I am sad to see that Apple still has not fixed the issue, considering they have had this bug report for well over four months.

  2. Tom Ferris Said,

    February 20, 2007 @ 9:33 am

    You and me both.. :)

  3. Matthew Berman Said,

    February 20, 2007 @ 6:20 pm

    hey tom,

    i dont really know what that means but i really like all the advice you give me…thanks for your help:)

    Matt

RSS feed for comments on this post · TrackBack URI

Leave a Comment