PT-2006-2475 · Apple · Itunes

Published

2006-06-29

·

Updated

2018-10-18

·

CVE-2006-1467

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions iTunes versions prior to 6.0.5
Description The issue is related to an integer overflow in the AAC file parsing code, which allows remote user-assisted attackers to execute arbitrary code via a specially crafted AAC file. The file must contain a sample table size (STSZ) atom with a sample size table value that is considered "malformed". This can be exploited when a user opens the malicious AAC file, potentially leading to arbitrary code execution.
Recommendations For versions prior to 6.0.5, update to version 6.0.5 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-1467

Affected Products

Itunes