CVE-2006-1453: Buffer Overflow
Published May 12, 2006
·Updated
Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information.
Affected Software
23 affected components
QuickTime Player<=7.0.4
QuickTime Player=3.0
QuickTime Player=4.1.2
QuickTime Player=5.0
QuickTime Player=5.0.1
QuickTime Player=6.0
QuickTime Player=6.0.1
QuickTime Player=6.0.2
QuickTime Player=6.1
QuickTime Player=6.1.0
QuickTime Player=6.1.1
QuickTime Player=6.2.0
QuickTime Player=6.3.0
QuickTime Player=6.4.0
QuickTime Player=6.5
QuickTime Player=6.5.0
QuickTime Player=6.5.1
QuickTime Player=6.5.2
QuickTime Player=7.0
QuickTime Player=7.0.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
QuickTime Player=7.0.3
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 12, 2006
CVE Published
08:06 PM
May 13, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1453?
The severity of CVE-2006-1453 is considered high due to its potential for remote code execution.
2
How do I fix CVE-2006-1453?
To fix CVE-2006-1453, update Apple QuickTime to version 7.1 or later.
3
What versions of QuickTime are affected by CVE-2006-1453?
CVE-2006-1453 affects multiple versions of Apple QuickTime from 3.0 up to and including 7.0.4.
4
Can CVE-2006-1453 be exploited remotely?
Yes, CVE-2006-1453 can be exploited remotely through a crafted QuickDraw PICT image.
5
What are the potential consequences of CVE-2006-1453?
The potential consequences of CVE-2006-1453 include arbitrary code execution that can lead to system compromise.