Apple iChat contains a flaw related to the way that aim URIs are handled by a printable format string that may allow an attacker to execute arbitrary code in the context of the user.
Classification
Location:
Remote / Network Access,
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Disclosure:
Vendor Verified
Solution
Apple Inc. has released a patch to address this issue. Additionally, it is possible to correct the flaw by implementing the following workaround(s):
Disable the aim URI handler using RCDefaultApp