PT-2006-6388 · Apple · Quartz Composer+1

Geoff Beier

·

Published

2006-12-20

·

Updated

2011-03-08

·

CVE-2006-5681

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: QuickTime for Java versions 10.4 through 10.4.8
Description: The issue allows remote attackers to obtain sensitive information, specifically screen images, via a Java applet. This occurs when QuickTime for Java is used with Quartz Composer and accesses images being rendered by other embedded QuickTime objects.
Recommendations: For versions 10.4 through 10.4.8, consider disabling the use of Java applets with Quartz Composer to minimize the risk of exploitation. Restrict access to sensitive information and screen images to prevent unauthorized access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5681

Affected Products

Quartz Composer
Quicktime For Java