7.6
CVSSv2

CVE-2007-0465

Published: 31/01/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote malicious users to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.

Vulnerable Product Search on Vulmon Subscribe to Product

apple installer 2.1.5

apple mac os x 10.4.8

Exploits

source: wwwsecurityfocuscom/bid/22272/info Apple Installer is prone to a format-string vulnerability because the application fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function A successful attack may crash the application or possibly allow the attacker to execute arb ...