PT-2006-6388 · Apple · Quartz Composer+1

Geoff Beier

·

Publicado

2006-12-20

·

Atualizado

2011-03-08

·

CVE-2006-5681

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: QuickTime for Java versions 10.4 through 10.4.8
Description: The issue allows remote attackers to obtain sensitive information, specifically screen images, via a Java applet. This occurs when QuickTime for Java is used with Quartz Composer and accesses images being rendered by other embedded QuickTime objects.
Recommendations: For versions 10.4 through 10.4.8, consider disabling the use of Java applets with Quartz Composer to minimize the risk of exploitation. Restrict access to sensitive information and screen images to prevent unauthorized access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5681

Produtos afetados

Quartz Composer
Quicktime For Java