SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#907836

Apple iTunes fails to properly parse AAC files

Overview

Apple iTunes does not properly parse AAC files. This vulnerability may allow a remote attacker to execute arbitrary code.

I. Description

Apple iTunes

Apple iTunes is a digital media player available for the Microsoft Windows and Mac OS X operating systems.

Advanced Audio Coding (AAC) file format

According to Apple,

    Advanced Audio Coding (AAC) is at the core of the MPEG-4, 3GPP and 3GPP2 specifications and is the audio codec of choice for Internet, wireless and digital broadcast arenas. AAC provides audio encoding that compresses much more efficiently than older formats, such as MP3, yet delivers quality rivaling that of uncompressed CD audio.
The AAC format is used in files with .M4P, .M4A, and .M4B extensions.

The Problem

Apple iTunes contains an integer overflow in the code used to parse AAC files. If a remote unauthenticated attacker persuades a user to access a specially crafted AAC file with iTunes, that attacker may be able to trigger the overflow.

Note that this vulnerability affects iTunes for Mac OS X and Microsoft Windows. For more information refer to the Security Content for iTunes 6.0.5.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code.

III. Solution

Upgrade iTunes

Apple has release iTunes 6.0.5 to address this issue.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Vulnerable30-Jun-2006

References


http://docs.info.apple.com/article.html?artnum=303952
http://www.zerodayinitiative.com/advisories/ZDI-06-020.html
http://secunia.com/advisories/20891/

Credit

Thanks to Apple Product Security for reporting this vulnerability. Apple, in turn, credits ATmaCA working with TippingPoint and the Zero Day Initiative for reporting this issue.

This document was written by Chad R Dougherty and Jeff Gennari.

Other Information

Date Public:2006-06-29
Date First Published:2006-06-30
Date Last Updated:2006-06-30
CERT Advisory: 
CVE-ID(s):CVE-2006-1467
NVD-ID(s):CVE-2006-1467
US-CERT Technical Alerts: 
Metric:11.73
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader