CVE-2006-1249: Integer Overflow
Published Mar 19, 2006
·Updated
Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks.
Affected Software
4 affected components
Apple iTunes=6.0.2
Apple Quicktime=7.0.3
Apple iTunes=6.0.1
Apple Quicktime=7.0.4
Event History
Mar 19, 2006
CVE Published
01:02 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1249?
CVE-2006-1249 is rated as high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2006-1249?
To fix CVE-2006-1249, upgrade to Apple QuickTime Player 7.0.5 or later and iTunes 6.0.3 or later.
3
Which versions of software are affected by CVE-2006-1249?
CVE-2006-1249 affects Apple QuickTime Player versions 7.0.3 and 7.0.4, and Apple iTunes versions 6.0.1 and 6.0.2.
4
What type of vulnerability is CVE-2006-1249?
CVE-2006-1249 is an integer overflow vulnerability that can lead to arbitrary code execution.
5
Can CVE-2006-1249 be exploited remotely?
Yes, CVE-2006-1249 can be exploited remotely through malicious FlashPix images.