CVE-2006-1467

Description

Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a malformed sample_size_table value.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
29.729

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Apple iTunes (X64) 6.0.4Windows
Multiple vulnerabilities affected in Apple iTunes 6.0.4Windows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 6.0.4Windows
Multiple Vulnerabilities are affected in Apple iTunes 6.0.4Windows
Vulnerabilities CVE-2006-1467 are affected in Apple iTunes For Mac 6.0.4--Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342817Apple iTunes (X64) (12.13.4.4)
PATCH-342816Apple iTunes (12.13.4.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234