CVE-2006-1552

UnknownEPSS 4.36%

Last modified

CVE-2006-1552 is a vulnerability of currently unknown severity. Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".. EPSS estimates a 4.36% chance of exploitation in the next 30 days.

Description

Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".

Metrics

EPSS Probability
4.36%

90.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AppleSafari1.0
AppleSafari1.1
AppleSafari1.2
AppleSafari1.2.1
AppleSafari1.2.2
AppleSafari1.2.3
AppleSafari1.3
AppleSafari2.0
AppleSafari2.0.1
AppleSafari2.0.2
AppleSafari2.0_pre
AppleSafaribeta2
AppleImageioAll versions
AppleMac Os X10.4
AppleMac Os X10.4.1
AppleMac Os X10.4.2
AppleMac Os X10.4.3
AppleMac Os X10.4.4
AppleMac Os X10.4.5
AppleMac Os X Server10.4
AppleMac Os X Server10.4.1
AppleMac Os X Server10.4.2
AppleMac Os X Server10.4.3
AppleMac Os X Server10.4.4
AppleMac Os X Server10.4.5

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-1552?
Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".
How severe is CVE-2006-1552?
Severity scoring for CVE-2006-1552 is pending analysis. The EPSS model estimates a 4.36% probability of exploitation in the next 30 days.
How do I fix CVE-2006-1552?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-1552?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST