PT-2006-2475 · Apple · Itunes
Publicado
2006-06-29
·
Atualizado
2018-10-18
·
CVE-2006-1467
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
iTunes versions prior to 6.0.5
Description
The issue is related to an integer overflow in the AAC file parsing code, which allows remote user-assisted attackers to execute arbitrary code via a specially crafted AAC file. The file must contain a sample table size (STSZ) atom with a
sample size table value that is considered "malformed". This can be exploited when a user opens the malicious AAC file, potentially leading to arbitrary code execution.Recommendations
For versions prior to 6.0.5, update to version 6.0.5 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Itunes