iLife Photocast XML Title Format String Variant 1

Strike ID:
E07-01f02
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2007

Description

This strike exploits a format string vulnerability in Apple iLife. The flaw lies in the parsing of the the title field of an iPhoto RSS feed. By convincing a user to subscribe to a malicious RSS Feed, an attacker could remotely execute arbitrary code. This strike emulates the original PoC.

CVE

Bid