PT-2006-2475 · Apple · Itunes
Published
2006-06-29
·
Updated
2018-10-18
·
CVE-2006-1467
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
iTunes versions prior to 6.0.5
Description
The issue is related to an integer overflow in the AAC file parsing code, which allows remote user-assisted attackers to execute arbitrary code via a specially crafted AAC file. The file must contain a sample table size (STSZ) atom with a
sample size table value that is considered "malformed". This can be exploited when a user opens the malicious AAC file, potentially leading to arbitrary code execution.Recommendations
For versions prior to 6.0.5, update to version 6.0.5 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Itunes