Apple updates iPhoto 7.1.2 with a security fix

By Robert Vamosi on 07 February 2008

Tags: iphoto | vulnerable | security | ilife | apple | mac os

A new security update is available for Mac OS X users running the program that's part of iLife 08.

On Tuesday, Apple issued a security update for iPhoto. The update is for users of Mac OS X v10.4.9 or later running iPhoto '08 (part of iLife 08). It addresses the vulnerability detailed in CVE-2008-0043.

To be vulnerable, Apple says, a user must subscribe to a maliciously crafted photocast. A remote attacker may then execute arbitrary code on the compromised machine. The fix addresses how iPhoto handles format strings when processing photocast subscriptions.

Apple credits Nathan McFeters of Ernst & Young's Advanced Security Center for reporting this vulnerability.

Like this article? Click below to send it to your mobile for free!

Be the first to comment on this article!

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • Hacker talks fooling e-passport systems

  • Best free Windows Mobile software

  • Trend Micro PC-cillin Internet Security 2009

  • Norton Internet Security 2009: Photos

  • Trend Micro Internet Security 2009 Pro: Photos

  • 101 software tips, tweaks and tricks

  • Don't buy stand-alone antivirus: Trend Micro

  • Norton Internet Security 2009

  • Spyware Terminator

More articles »

Find the right software

Brand
  • Multiple options can be selected

    • Trend Micro PC-cillin Internet Security 2009

      Trend Micro PC-cillin Internet Security 2009

      You can't beat the price. For a good, basic internet security suite, we recommend Trend Micro Internet Security 2009.

    • Norton Internet Security 2009

      Norton Internet Security 2009

      Norton Internet Security 2009 hits all the right security notes and its superior protection technologies might even win back some jaded anti-Symantec folks, though the lack of adequate technical support may continue to frustrate.

    • Spyware Terminator

      Spyware Terminator

      This spyware scanner and removal tool does the job, but enabling some functions may cause slight slowdowns and it has a few bugs in Vista.

    • ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security 2009 provides top-notch security protection that is light on system resources, allowing you to work unencumbered.

    • Ad-Aware 2008

      Ad-Aware 2008

      This year's update to user favourite Ad-Aware is quite a significant overhaul, and the result is faster scan times and a new interface.

    More reviews »

    Membership benefits

    Win prizes and other promotion benefits

    Win prizes and other promotion benefits

    As a CNET.com.au member, you're eligible to enter and win any prizes on our site. Sign up for a free CNET.com.au membership now!