PT-2006-2265 · Apple · Quicktime Player+1
Jeff Gennari
·
Published
2006-03-18
·
Updated
2018-10-18
·
CVE-2006-1249
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apple QuickTime Player versions 7.0.3 through 7.0.4
iTunes versions 6.0.1 through 6.0.2
Description
The issue is related to an integer overflow in the handling of FlashPix (FPX) images. This overflow can be triggered by a specially crafted FPX image that contains a field specifying a large number of blocks, allowing remote attackers to execute arbitrary code.
Recommendations
For Apple QuickTime Player versions 7.0.3 through 7.0.4, consider updating to a newer version to resolve the issue.
For iTunes versions 6.0.1 through 6.0.2, consider updating to a newer version to resolve the issue.
As a temporary workaround, consider avoiding the use of FlashPix (FPX) images in Apple QuickTime Player and iTunes until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quicktime Player
Itunes