Описание
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
Ссылки
- ExploitVendor Advisory
- Vendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:apple:iphoto:6.0.5:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.09103
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-134
Связанные уязвимости
github
больше 4 лет назад
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
EPSS
Процентиль: 95%
0.09103
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-134