Security Advisory
CVE-2015-3716
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.