CVE-2006-2238: Buffer Overflow
Published May 12, 2006
·Updated
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, but it has been given a separate identifier because it is a distinct issue.
Affected Software
5 affected components
QuickTime Player<=7.0.4
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
QuickTime Player=7.0.3
Remediation
Event History
May 12, 2006
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2238?
CVE-2006-2238 is considered critical due to the potential for remote code execution.
2
How do I fix CVE-2006-2238?
To fix CVE-2006-2238, update Apple QuickTime to version 7.1 or later.
3
What causes the vulnerability CVE-2006-2238?
CVE-2006-2238 is caused by a heap-based buffer overflow in the ReadBMP function.
4
Which versions of Apple QuickTime are affected by CVE-2006-2238?
CVE-2006-2238 affects Apple QuickTime versions prior to 7.1, including all versions from 7.0.0 to 7.0.4.
5
Can CVE-2006-2238 be exploited remotely?
Yes, CVE-2006-2238 can be exploited remotely through a malicious BMP file.