First published: Wed Jan 31 2007(Updated: )
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Installer | =2.1.5 | |
macOS Yosemite | =10.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0465 is considered a moderate severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2007-0465, update Apple Installer to a version later than 2.1.5.
CVE-2007-0465 affects Apple Installer 2.1.5 and Mac OS X 10.4.8.
Attackers can exploit CVE-2007-0465 using malicious format string specifiers in package filenames.
Yes, exploiting CVE-2007-0465 requires user-assisted actions to execute the malicious package.