CVE-2006-1454: Buffer Overflow
Published May 12, 2006
·Updated
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data.
Affected Software
2 affected components
QuickTime Player=7.0.3
QuickTime Player=7.0.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 12, 2006
CVE Published
08:06 PM
May 13, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1454?
CVE-2006-1454 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2006-1454?
To fix CVE-2006-1454, update Apple QuickTime to version 7.1 or later.
3
What software is affected by CVE-2006-1454?
CVE-2006-1454 affects Apple QuickTime versions 7.0.3 and 7.0.4.
4
Can CVE-2006-1454 be exploited remotely?
Yes, CVE-2006-1454 can be exploited by remote attackers through crafted QuickDraw PICT image files.
5
What type of vulnerability is CVE-2006-1454?
CVE-2006-1454 is a heap-based buffer overflow vulnerability.