Format String Vulnerability in Apple Installer on Mac OS X
CVE-2007-0465

Currently unrated

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
31 January 2007

Summary

A format string vulnerability exists in Apple Installer 2.1.5 running on Mac OS X 10.4.8, which can be exploited by user-assisted remote attackers. This vulnerability allows the execution of arbitrary code due to inadequate handling of format string specifiers in package filenames, including PKG, DISTZ, or MPKG files. If successfully exploited, the attacker could gain unauthorized access to the system, highlighting the importance of utilizing secure software practices and regularly updating software to mitigate such risks.

References

EPSS Score

35% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.