PT-2006-2265 · Apple · Quicktime Player+1

Jeff Gennari

·

Publicado

2006-03-18

·

Atualizado

2018-10-18

·

CVE-2006-1249

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apple QuickTime Player versions 7.0.3 through 7.0.4 iTunes versions 6.0.1 through 6.0.2
Description The issue is related to an integer overflow in the handling of FlashPix (FPX) images. This overflow can be triggered by a specially crafted FPX image that contains a field specifying a large number of blocks, allowing remote attackers to execute arbitrary code.
Recommendations For Apple QuickTime Player versions 7.0.3 through 7.0.4, consider updating to a newer version to resolve the issue. For iTunes versions 6.0.1 through 6.0.2, consider updating to a newer version to resolve the issue. As a temporary workaround, consider avoiding the use of FlashPix (FPX) images in Apple QuickTime Player and iTunes until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-1249

Produtos afetados

Quicktime Player
Itunes