CVE-2010-0042

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.
References
Link Resource
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html
http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html Vendor Advisory
http://secunia.com/advisories/39135
http://secunia.com/advisories/42314
http://support.apple.com/kb/HT4070 Vendor Advisory
http://support.apple.com/kb/HT4077
http://support.apple.com/kb/HT4105
http://support.apple.com/kb/HT4225
http://support.apple.com/kb/HT4456
http://www.securityfocus.com/bid/38671 Patch
http://www.securityfocus.com/bid/38677 Patch
http://www.securitytracker.com/id?1023706
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7561
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html
http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html Vendor Advisory
http://secunia.com/advisories/39135
http://secunia.com/advisories/42314
http://support.apple.com/kb/HT4070 Vendor Advisory
http://support.apple.com/kb/HT4077
http://support.apple.com/kb/HT4105
http://support.apple.com/kb/HT4225
http://support.apple.com/kb/HT4456
http://www.securityfocus.com/bid/38671 Patch
http://www.securityfocus.com/bid/38677 Patch
http://www.securitytracker.com/id?1023706
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7561
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:4.0.3:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:11

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html - () http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html -
References () http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html - () http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html -
References () http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html - () http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html -
References () http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html - () http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html -
References () http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html - Vendor Advisory () http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html - Vendor Advisory
References () http://secunia.com/advisories/39135 - () http://secunia.com/advisories/39135 -
References () http://secunia.com/advisories/42314 - () http://secunia.com/advisories/42314 -
References () http://support.apple.com/kb/HT4070 - Vendor Advisory () http://support.apple.com/kb/HT4070 - Vendor Advisory
References () http://support.apple.com/kb/HT4077 - () http://support.apple.com/kb/HT4077 -
References () http://support.apple.com/kb/HT4105 - () http://support.apple.com/kb/HT4105 -
References () http://support.apple.com/kb/HT4225 - () http://support.apple.com/kb/HT4225 -
References () http://support.apple.com/kb/HT4456 - () http://support.apple.com/kb/HT4456 -
References () http://www.securityfocus.com/bid/38671 - Patch () http://www.securityfocus.com/bid/38671 - Patch
References () http://www.securityfocus.com/bid/38677 - Patch () http://www.securityfocus.com/bid/38677 - Patch
References () http://www.securitytracker.com/id?1023706 - () http://www.securitytracker.com/id?1023706 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7561 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7561 -

Information

Published : 2010-03-15 13:28

Updated : 2024-11-21 01:11


NVD link : CVE-2010-0042

Mitre link : CVE-2010-0042

CVE.ORG link : CVE-2010-0042


JSON object : View

Products Affected

apple

  • safari

microsoft

  • windows
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor