vendor:
iPhoto
by:
milw0rm.com
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: iPhoto
Affected Version From: iPhoto 4.0.3
Affected Version To: iPhoto 4.0.3
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:iphoto:4.0.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Crash the iPhoto DPAP Server on iPhoto 4.0.3
This exploit crashes the iPhoto DPAP (Digital Photo Access Protocol) Server on iPhoto 4.0.3. The server exits cleanly but it does not restart. The exploit sends a malformed GET request to the server, which causes it to crash. The loop is unnecessary but it does the job.
Mitigation:
Upgrade to the latest version of iPhoto.