ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.
lists.apple.com/archives/security-announce/2010//Mar/msg00001.html
lists.apple.com/archives/security-announce/2010//Mar/msg00003.html
lists.apple.com/archives/security-announce/2010/Jun/msg00003.html
lists.apple.com/archives/security-announce/2010/Mar/msg00000.html
secunia.com/advisories/39135
support.apple.com/kb/HT4070
support.apple.com/kb/HT4077
support.apple.com/kb/HT4105
support.apple.com/kb/HT4225
www.securityfocus.com/bid/38671
www.securityfocus.com/bid/38676
www.securitytracker.com/id?1023706
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6885