>> Apple iPhoto Photocast Handling Remote Format String Vulnerability
Title : Apple iPhoto Photocast Handling Remote Format String Vulnerability VUPEN ID : VUPEN/ADV-2008-0428 CVE ID : CVE-2008-0043
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-02-06
Technical Description
A vulnerability has been identified in Apple iPhoto, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a format string error when processing photocast subscriptions, which could be exploited by attackers to crash a vulnerable application or execute arbitrary code by tricking a user into subscribing to a specially crafted photocast.