PT-2006-2265 · Apple · Quicktime Player+1

Jeff Gennari

·

Published

2006-03-18

·

Updated

2018-10-18

·

CVE-2006-1249

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apple QuickTime Player versions 7.0.3 through 7.0.4 iTunes versions 6.0.1 through 6.0.2
Description The issue is related to an integer overflow in the handling of FlashPix (FPX) images. This overflow can be triggered by a specially crafted FPX image that contains a field specifying a large number of blocks, allowing remote attackers to execute arbitrary code.
Recommendations For Apple QuickTime Player versions 7.0.3 through 7.0.4, consider updating to a newer version to resolve the issue. For iTunes versions 6.0.1 through 6.0.2, consider updating to a newer version to resolve the issue. As a temporary workaround, consider avoiding the use of FlashPix (FPX) images in Apple QuickTime Player and iTunes until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1249

Affected Products

Quicktime Player
Itunes