Vulnerability Details CVE-2006-1467
Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.358
EPSS Ranking 97.0%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2006-1467
-
-
cpe:2.3:a:apple:itunes:4.0.0
-
cpe:2.3:a:apple:itunes:4.0.1
-
cpe:2.3:a:apple:itunes:4.1.0
-
cpe:2.3:a:apple:itunes:4.2.0
-
cpe:2.3:a:apple:itunes:4.5
-
cpe:2.3:a:apple:itunes:4.5.0
-
cpe:2.3:a:apple:itunes:4.6
-
cpe:2.3:a:apple:itunes:4.6.0
-
cpe:2.3:a:apple:itunes:4.7
-
cpe:2.3:a:apple:itunes:4.7.0
-
cpe:2.3:a:apple:itunes:4.7.1
-
cpe:2.3:a:apple:itunes:4.7.2
-
cpe:2.3:a:apple:itunes:4.8.0
-
cpe:2.3:a:apple:itunes:4.9.0
-
cpe:2.3:a:apple:itunes:5.0
-
cpe:2.3:a:apple:itunes:5.0.0
-
cpe:2.3:a:apple:itunes:5.0.1
-
cpe:2.3:a:apple:itunes:6.0.0
-
cpe:2.3:a:apple:itunes:6.0.1
-
cpe:2.3:a:apple:itunes:6.0.2
-
cpe:2.3:a:apple:itunes:6.0.3
-
cpe:2.3:a:apple:itunes:6.0.4