CVE-2006-1467: Integer Overflow
Published Jun 29, 2006
·Updated
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" samplesizetable value.
Affected Software
1 affected component
Apple iTunes<=6.0.4
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jun 29, 2006
CVE Published
11:05 PM
Jun 30, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1467?
CVE-2006-1467 is rated as high severity due to its potential to allow remote execution of arbitrary code.
2
How do I fix CVE-2006-1467?
To mitigate CVE-2006-1467, update Apple iTunes to version 6.0.5 or later.
3
Which versions of Apple iTunes are affected by CVE-2006-1467?
CVE-2006-1467 affects Apple iTunes versions prior to 6.0.5.
4
What type of attack is associated with CVE-2006-1467?
CVE-2006-1467 is associated with remote user-assisted attacks via specially crafted AAC files.
5
What platforms are vulnerable to CVE-2006-1467?
CVE-2006-1467 affects users on Mac OS X 10.2.8 or later, as well as Windows XP and 2000.