CVE-2006-1460: Buffer Overflow
Published May 12, 2006
·Updated
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.
Affected Software
5 affected components
QuickTime Player<=7.0.4
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
QuickTime Player=7.0.3
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 12, 2006
CVE Published
08:06 PM
May 13, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1460?
CVE-2006-1460 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2006-1460?
To fix CVE-2006-1460, update Apple QuickTime to version 7.1 or later.
3
What types of attacks can exploit CVE-2006-1460?
CVE-2006-1460 can be exploited through crafted QuickTime movie files that trigger buffer overflows.
4
Which versions of QuickTime are affected by CVE-2006-1460?
CVE-2006-1460 affects multiple QuickTime versions including 7.0, 7.0.1, 7.0.2, and 7.0.3.
5
What is the impact of CVE-2006-1460 on affected systems?
The impact of CVE-2006-1460 includes the potential for attackers to execute arbitrary code on affected systems.