Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.351
EPSS Ranking 96.8%