Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-1467

Overview

Vulnerability Score 5.1 5.1
CVE Id CVE-2006-1467
Last Modified 07 Mar 2011 12:00:00
Published 29 Jun 2006 07:05:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2006-1467

Summary

Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.

Vulnerable Systems

Application

  • Apple Itunes 6.0.4


References

CERT-VN - VU#907836

SECUNIA - 20891

APPLE - APPLE-SA-2006-06-29

XF - itunes-aac-file-overflow(27481)

MISC - http://www.zerodayinitiative.com/advisories/ZDI-06-020.html

VUPEN - ADV-2006-2601

BID - 18730

BUGTRAQ - 20060630 ZDI-06-020: Apple iTunes AAC File Parsing Integer Overflow Vulnerability

SECTRACK - 1016413

Related Patches

Apple 2006-06-29 iTunes 6.0.5 (SEE NOTES) (Rev 6)


Last Updated: 27 May 2016 10:42:05