Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2007-01-31 16:28
Updated : 2011-03-06 21:00
NVD link : CVE-2007-0646
Mitre link : CVE-2007-0646
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
apple
- mac_os_x
- safari
- imovie