CVE-2007-0051

Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apple:iphoto:6.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 00:24

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0100.html - () http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0100.html -
References () http://docs.info.apple.com/article.html?artnum=305215 - () http://docs.info.apple.com/article.html?artnum=305215 -
References () http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html - () http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html -
References () http://osvdb.org/31165 - () http://osvdb.org/31165 -
References () http://projects.info-pull.com/moab/MOAB-04-01-2007.html - Exploit, Vendor Advisory () http://projects.info-pull.com/moab/MOAB-04-01-2007.html - Exploit, Vendor Advisory
References () http://secunia.com/advisories/23615 - Vendor Advisory () http://secunia.com/advisories/23615 - Vendor Advisory
References () http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt - () http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt -
References () http://www.securityfocus.com/archive/1/455968/100/0/threaded - () http://www.securityfocus.com/archive/1/455968/100/0/threaded -
References () http://www.securityfocus.com/bid/21871 - () http://www.securityfocus.com/bid/21871 -
References () http://www.vupen.com/english/advisories/2007/0057 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/0057 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/31281 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/31281 -
References () https://www.exploit-db.com/exploits/3080 - () https://www.exploit-db.com/exploits/3080 -

07 Nov 2023, 02:00

Type Values Removed Values Added
References
  • {'url': 'http://www.digitalmunition.com/DMA[2007-0104a].txt', 'name': 'http://www.digitalmunition.com/DMA[2007-0104a].txt', 'tags': ['Broken Link'], 'refsource': 'MISC'}
  • () http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt -

Information

Published : 2007-01-04 18:28

Updated : 2024-11-21 00:24


NVD link : CVE-2007-0051

Mitre link : CVE-2007-0051

CVE.ORG link : CVE-2007-0051


JSON object : View

Products Affected

apple

  • iphoto
CWE
CWE-134

Use of Externally-Controlled Format String