6.8
CVSSv2

CVE-2008-2304

Published: 14/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in Apple Core Image Fun House 2.0 and previous versions in CoreImage Examples in Xcode tools prior to 3.1 allows user-assisted malicious users to execute arbitrary code or cause a denial of service (application crash) via a .funhouse file with a string XML element that contains many characters.

Vulnerable Product Search on Vulmon Subscribe to Product

apple core image fun house

Exploits

#!/usr/bin/ruby # Copyright (c) Netragard, LLC adriel@netragardcom # # /Developer/Applications/Graphics Tools/Core Image Fun Houseapp # /Contents/MacOS/Core Image Fun House # # (gdb) x/10s 0xbfffddf7 # 0xbfffddf7: 'Z' <repeats 101 times>, "DCBA center" # # 2007-07-10 21:15:34573 Core Image Fun House[1061] CFLog (0): # CFProper ...