Apple today issued updates to its iPhoto, Braille Display, and ProKit software. The newly released iPhoto 7.1.2 addresses issues when publishing photos to a .Mac Web Gallery, improves overall stability, and fixes several other minor issues, according to Apple. The issue could arise when users subscribe to a maliciously crafted photocast, which may lead to arbitrary code execution.
"A format string vulnerability exists in iPhoto. By enticing a user to subscribe to a maliciously crafted photocast, a remote attacker may cause arbitrary code execution. This update addresses the issue through improved handling of format strings when processing photocast subscriptions," Apple wrote. "Credit to Nathan McFeters of Ernst & Young's Advanced Security Center for reporting this issue."
Braille Display
Apple's Braille Display Update 1.0 adds support to Apple's screen reading software, called VoiceOver, in Mac OS X 10.5 with additional refreshable Braille displays: