HIGH
Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI
Published Jan 23, 2007
7.5
HIGHCVSS 2.0
EPSS 23.13%
Description
Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (12)
- http://docs.info.apple.com/article.html?artnum=305102 x_refsource_CONFIRM
- http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html vendor-advisoryx_refsource_APPLE
- http://osvdb.org/32715 vdb-entryx_refsource_OSVDB
- http://projects.info-pull.com/moab/MOAB-20-01-2007.html x_refsource_MISCExploitVendor Advisory
- http://secunia.com/advisories/24198 third-party-advisoryx_refsource_SECUNIA
- http://www.kb.cert.org/vuls/id/794752 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.securityfocus.com/bid/22146 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1017661 vdb-entryx_refsource_SECTRACK
- http://www.us-cert.gov/cas/techalerts/TA07-047A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2007/0274 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-0025 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31679 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://docs.info.apple.com/article.html?artnum=305102 | x_refsource_CONFIRM | |
| http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html | vendor-advisoryx_refsource_APPLE | |
| http://osvdb.org/32715 | vdb-entryx_refsource_OSVDB | |
| http://projects.info-pull.com/moab/MOAB-20-01-2007.html | x_refsource_MISCExploitVendor Advisory | |
| http://secunia.com/advisories/24198 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.kb.cert.org/vuls/id/794752 | third-party-advisoryx_refsource_CERT-VNUS Government Resource | |
| http://www.securityfocus.com/bid/22146 | vdb-entryx_refsource_BID | |
| http://www.securitytracker.com/id?1017661 | vdb-entryx_refsource_SECTRACK | |
| http://www.us-cert.gov/cas/techalerts/TA07-047A.html | third-party-advisoryx_refsource_CERTUS Government Resource | |
| http://www.vupen.com/english/advisories/2007/0274 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-0025 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/31679 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 23, 2007
Updated Aug 7, 2024
Reserved Jan 2, 2007
Link CVE-2007-0021
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2007-0025 Assigner mitre
Published Jan 23, 2007
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2007-0025