CVE-2006-1467
published 2006-06-29CVE-2006-1467: Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted…
PriorityP425medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
7.02%
93.5th percentile
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | <= 6.0.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://docs.info.apple.com/article.html?artnum=303952http://secunia.com/advisories/20891http://securitytracker.com/id?1016413http://www.kb.cert.org/vuls/id/907836http://www.securityfocus.com/archive/1/438812/100/0/threadedhttp://www.securityfocus.com/bid/18730http://www.vupen.com/english/advisories/2006/2601http://www.zerodayinitiative.com/advisories/ZDI-06-020.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/27481http://docs.info.apple.com/article.html?artnum=303952http://secunia.com/advisories/20891http://securitytracker.com/id?1016413http://www.kb.cert.org/vuls/id/907836http://www.securityfocus.com/archive/1/438812/100/0/threadedhttp://www.securityfocus.com/bid/18730http://www.vupen.com/english/advisories/2006/2601http://www.zerodayinitiative.com/advisories/ZDI-06-020.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/27481
2006-06-29
Published