CVE-2006-1467
Apple iTunes < 6.0.5 - Remote Code Execution via Malformed AAC File Sample Table Size Atom
Title source: llmDescription
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.
References (9)
Core 9
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2601
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1016413
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-06-020.html
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20891
Patch, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/907836
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/438812/100/0/threaded
Patch vendor-advisory
x_refsource_apple
http://docs.info.apple.com/article.html?artnum=303952
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27481
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/18730
Scores
EPSS
0.0702
EPSS Percentile
93.5%
Details
CWE
CWE-189
Status
published
Products (1)
apple/itunes
< 6.0.4
Published
Jun 29, 2006
Tracked Since
Feb 18, 2026