Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-0646
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-0646

Description:
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA24966
  Secunia Advisory: SA27643

MISC
  http://www.digitalmunition.com/MOAB-30-01-2007.html

CONFIRM
  http://docs.info.apple.com/article.html?artnum=307041
  http://docs.info.apple.com/article.html?artnum=305391

CERT
  http://www.us-cert.gov/cas/techalerts/TA07-109A.html
  http://www.us-cert.gov/cas/techalerts/TA07-319A.html

BID
  22326
  26444

APPLE
  http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html
  http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html


Return to the previous page.