Apple Mac OS X is vulnerable to a heap-based buffer overflow in the ReadBMP() function. By creating a malicious BMP file and persuading a victim to open the file using either Safari or the Preview application, a remote attacker could overflow a buffer and cause the affected application to crash or possibly execute arbitrary code on the system. An attacker could exploit this vulnerability by hosting the malicious file on a Web site or sending it to a victim as an email attachment.