Format String Vulnerability in Apple Software Update for Mac OS X
CVE-2007-0463

Currently unrated

Key Information:

Vendor

Apple

Vendor
CVE Published:
29 January 2007

What is CVE-2007-0463?

A format string vulnerability exists in Apple Software Update version 2.0.5 on Mac OS X 10.4.8. This flaw allows remote attackers to manipulate format string specifiers in SWUTMP and SUCATALOG filenames, or by sending specially crafted application/x-apple.sucatalog+xml MIME types. Exploitation of this vulnerability can result in a denial of service through application crashes or potentially allow for the execution of arbitrary code, posing significant risks to system integrity.

References

EPSS Score

34% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.