A local format string flaw exists in Mac OS X. The Help Viewer fails to validate the filename for .help files resulting in possible format string execution. With a specially crafted file, an attacker can cause arbitrary code execution resulting in a loss of integrity.
Classification
Location:
Local Access Required,
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Public
Technical
A bug in CoreFoundation makes it difficult to exploit this flaw for code execution.
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.