Brief Hands-On Report--Apple released iPhoto 6.0.6
This update to iPhoto addresses issues associated with EXIF data compatibility and Photocasting.
Here are the details on the security fix:
Subscribing to a maliciously-crafted photocast may lead to arbitrary code execution--A format string vulnerability exists in iPhoto. By enticing a user to subscribe to a maliciously-crafted photocast, a remote attacker can trigger the vulnerability which may lead to arbitrary code execution. This has been described on the Month of Apple Bugs web site (MOAB-04-01-2007). This update addresses the issue by performing additional validation while handling photocast subscriptions. Credit to Kevin Finisterre of DigitalMunition for reporting this issue.
We downloaded and installed iPhoto 6.0.6 along with Mac OS X 10.4.9 without issue on the same Macs as noted above. Afterwards, we launched iPhoto and viewed a number of our stored photos with no problem. No update of the iPhoto database was performed. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?