CVE-2006-1463: Buffer Overflow
Published May 12, 2006
·Updated
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.
Affected Software
2 affected components
QuickTime Player=7.0.3
QuickTime Player=7.0.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 12, 2006
CVE Published
08:06 PM
May 13, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1463?
CVE-2006-1463 has been rated as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2006-1463?
To fix CVE-2006-1463, users should update to the latest version of QuickTime that addresses the buffer overflow issue.
3
What impact does CVE-2006-1463 have on affected software?
CVE-2006-1463 can allow remote attackers to execute arbitrary code on the system running affected versions of QuickTime.
4
Which versions of QuickTime are affected by CVE-2006-1463?
CVE-2006-1463 affects Apple QuickTime versions 7.0.3 and 7.0.4.
5
What type of attack can exploit CVE-2006-1463?
CVE-2006-1463 can be exploited through specially crafted H.264 (M4V) video format files.