Vulnerabilities > CVE-2005-1248 - Unspecified vulnerability in Apple Itunes
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN apple
nessus
Summary
Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_ITUNES_OVERFLOW2.NASL |
description | The remote host is running a version of iTunes which is older than version 4.8.0. Such versions reportedly fail to perform certain validation checks on MPEG4 files, and hence it could be possible to trigger a buffer overflow condition. Successful exploitation of this issue could lead to a denial of service condition or arbitrary code execution on the remote system. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18214 |
published | 2005-05-09 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18214 |
title | iTunes < 4.8.0 MPEG-4 Parsing Overflow (Mac OS X) |
code |
|
Oval
accepted | 2015-06-22T04:00:28.844-04:00 | ||||||||||||
class | vulnerability | ||||||||||||
contributors |
| ||||||||||||
definition_extensions |
| ||||||||||||
description | Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file. | ||||||||||||
family | windows | ||||||||||||
id | oval:org.mitre.oval:def:17304 | ||||||||||||
status | accepted | ||||||||||||
submitted | 2013-07-30T11:32:03.685-04:00 | ||||||||||||
title | Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file | ||||||||||||
version | 7 |
References
- http://lists.apple.com/archives/security-announce/2005/May/msg00003.html
- http://www.securityfocus.com/bid/13565
- http://www.osvdb.org/16243
- http://securitytracker.com/id?1013927
- http://secunia.com/advisories/15310
- http://www.ngssoftware.com/advisories/itunes.txt
- http://docs.info.apple.com/article.html?artnum=301596
- http://www.vupen.com/english/advisories/2005/0504
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20498
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17304