Apple iTunes AAC file integer overflow
| itunes-aac-file-overflow (27481) |
Description:
Apple iTunes is vulnerable to an integer overflow, caused by improper parsing of Advanced Audio Coding (AAC) files, which could lead to memory corruption. An attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash, if the attacker could persuade a potential victim to open a malicious .M4A or .M4P file containing a specially-crafted 'sample_size_table' value.
Platforms Affected:
- Apple, iTunes 6
- Apple, iTunes 6.0.1
- Apple, iTunes 6.0.2
- Apple, iTunes 6.0.2.23
- Apple, iTunes 6.0.3
- Apple, iTunes 6.0.4
Remedy:
Upgrade to the latest version of Apple iTunes (6.0.5 or later), available from the Apple Web site. See References.
Consequences:
Gain Access
References:
- Apple Security-Announce Mailing List, Thu, 29 Jun 2006 12:20:52 -0700 , APPLE-SA-2006-06-29 iTunes 6.0.5 at http://lists.apple.com/archives/Security-announce/2006/Jun/msg00001.html.
- iTunes 6.0.5, About the security content of iTunes 6.0.5 at http://docs.info.apple.com/article.html?artnum=303952.
- ZDI-06-020, Apple iTunes AAC File Parsing Integer Overflow Vulnerability at http://www.zerodayinitiative.com/advisories/ZDI-06-020.html.
- BID-18730: Apple iTunes AAC File Parsing Integer Overflow Vulnerability
- CVE-2006-1467: Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a malformed sample_size_table value.
- SA20891: Apple iTunes AAC File Parsing Integer Overflow Vulnerability
- SECTRACK ID: 1016413: iTunes Integer Overflow in Processing AAC Files Lets Remote Users Execute Arbitrary Code
- US-CERT VU#907836: Apple iTunes fails to properly parse AAC files
- VUPEN/ADV-2006-2601: Apple iTunes Advanced Audio Coding File Handling Integer Overflow Vulnerability
Reported:
Jun 28, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
