Vulnerabilities > CVE-2007-0645 - Products Format String vulnerability in Apple Iphoto 6.0.5

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
apple
exploit available

Summary

Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.

Vulnerable Configurations

Part Description Count
Application
Apple
1

Exploit-Db

descriptionApple Mac OS X 10.4.x iPhoto photo:// URL Handling Format String. CVE-2007-0645. Dos exploit for osx platform
idEDB-ID:29554
last seen2016-02-03
modified2007-01-30
published2007-01-30
reporterLMH
sourcehttps://www.exploit-db.com/download/29554/
titleApple Mac OS X 10.4.x iPhoto photo:// URL Handling Format String