VYPR
Unrated severityNVD Advisory· Published Jun 29, 2006· Updated Jun 16, 2026

CVE-2006-1467

CVE-2006-1467

Description

Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-assisted attackers to execute arbitrary code via an AAC (M4P, M4A, or M4B) file with a sample table size (STSZ) atom with a "malformed" sample_size_table value.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Apple Inc./iTunes2 versions
    cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*range: <=6.0.4
    • (no CPE)range: <6.0.5

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.