|
|
|
![]() |
Vulnerability Note VU#794752Apple iChat AIM URI handler format string vulnerabilityOverviewApple iChat contains a format string vulnerability. This vulnerability may allow a remote, unauthenticated attacker to execute arbitary code.I. DescriptionThe Apple iChat AIM URI handler fails to properly sanitize user-controlled data that is supplied to a formatted output function. This may allow a format string vulnerability to occur.Depending on the user's browser, an attacker may be able to exploit this vulnerability by persuading a user to access a specially crafted web page. Some web browsers, such as Safari, automatically launch iChat to handle certain types of URIs. So, if a Safari user accesses a web page containing a specially crafted URI, iChat will be launched to process that URI. This may trigger the vulnerability. Apple has addressed this issue with Apple Security Update 2007-002.
Referenceshttps://www.securecoding.cert.org/confluence/x/WwE This vulnerability was publicly disclosed as part of the Month of Apple Bugs project. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||