First published: Thu Feb 01 2007(Updated: )
Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0647 is classified as a medium severity vulnerability due to its potential to cause denial of service.
To fix CVE-2007-0647, updating to a version of macOS that does not have the vulnerability is recommended.
CVE-2007-0647 affects users running Help Viewer 3.0.0 on macOS version 10.3.9.
CVE-2007-0647 involves a remote user-assisted attack that can lead to application crashes.
Currently, there are no specific workarounds for CVE-2007-0647 other than upgrading to an unaffected version of macOS.