Brief Hands-On Report--Apple released iPhoto 6.0.6

iPhoto 6.0.6 is available for download via Software Update or as a stand-alone file from this Apple Web page. According to the Read Me file,

This update to iPhoto addresses issues associated with EXIF data compatibility and Photocasting.

Here are the details on the security fix:

Subscribing to a maliciously-crafted photocast may lead to arbitrary code execution--A format string vulnerability exists in iPhoto. By enticing a user to subscribe to a maliciously-crafted photocast, a remote attacker can trigger the vulnerability which may lead to arbitrary code execution. This has been described on the Month of Apple Bugs web site (MOAB-04-01-2007). This update addresses the issue by performing additional validation while handling photocast subscriptions. Credit to Kevin Finisterre of DigitalMunition for reporting this issue.

We downloaded and installed iPhoto 6.0.6 along with Mac OS X 10.4.9 without issue on the same Macs as noted above. Afterwards, we launched iPhoto and viewed a number of our stored photos with no problem. No update of the iPhoto database was performed. [Bill Fox & Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive