>> Apple iChat "aim" URI Handler Remote Format String and Denial of Service Vulnerability
Title : Apple iChat "aim" URI Handler Remote Format String and Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-0274 CVE ID : CVE-2007-0021
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-22
Technical Description
A vulnerability has been identified in Apple iChat, which could be exploited by attackers to cause a denial of service or potentially execute arbitrary commands. This issue is due to a format string error when handling an "aim://" URI with a specially crafted argument (e.g. "roomname"), which could be exploited by attackers to crash a vulnerable application or potentially compromise an affected system by tricking a user into visiting a specially crafted web page.