CVE-2007-5861: Medium severity Apple iOS and macOS vulnerability
Unspecified vulnerability in Spotlight in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted .XLS file that triggers memory corruption in the Microsoft Office Spotlight Importer.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs to convince a user to process a crafted .XLS file. Exploitation is user-assisted and relies on the Microsoft Office Spotlight Importer encountering the malicious file.
Which systems are explicitly identified as affected?
The vulnerability description identifies Spotlight in Apple Mac OS X 10.4.11. Although the software metadata lists Apple iOS and macOS, no specific iOS version is identified in the provided data.
What is the potential impact if exploitation succeeds?
The crafted .XLS file can trigger memory corruption, which may terminate an application or allow arbitrary code execution. The provided vector indicates network reachability, medium attack complexity, no authentication requirement, and impacts to confidentiality, integrity, and availability.