PT-2006-6388 · Apple · Quartz Composer+1
Geoff Beier
·
Published
2006-12-20
·
Updated
2011-03-08
·
CVE-2006-5681
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
QuickTime for Java versions 10.4 through 10.4.8
Description:
The issue allows remote attackers to obtain sensitive information, specifically screen images, via a Java applet. This occurs when QuickTime for Java is used with Quartz Composer and accesses images being rendered by other embedded QuickTime objects.
Recommendations:
For versions 10.4 through 10.4.8, consider disabling the use of Java applets with Quartz Composer to minimize the risk of exploitation. Restrict access to sensitive information and screen images to prevent unauthorized access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quartz Composer
Quicktime For Java