Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
References
Configurations
History
21 Nov 2024, 00:24
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0100.html - | |
References | () http://docs.info.apple.com/article.html?artnum=305215 - | |
References | () http://lists.apple.com/archives/security-announce/2007/Mar//msg00003.html - | |
References | () http://osvdb.org/31165 - | |
References | () http://projects.info-pull.com/moab/MOAB-04-01-2007.html - Exploit, Vendor Advisory | |
References | () http://secunia.com/advisories/23615 - Vendor Advisory | |
References | () http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt - | |
References | () http://www.securityfocus.com/archive/1/455968/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/21871 - | |
References | () http://www.vupen.com/english/advisories/2007/0057 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/31281 - | |
References | () https://www.exploit-db.com/exploits/3080 - |
07 Nov 2023, 02:00
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2007-01-04 18:28
Updated : 2024-11-21 00:24
NVD link : CVE-2007-0051
Mitre link : CVE-2007-0051
CVE.ORG link : CVE-2007-0051
JSON object : View
Products Affected
apple
- iphoto
CWE
CWE-134
Use of Externally-Controlled Format String