Vulnerability Name: | CVE-2005-1248 (CCN-20498) | ||||||||
Assigned: | 2005-05-09 | ||||||||
Published: | 2005-05-09 | ||||||||
Updated: | 2017-10-11 | ||||||||
Summary: | Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-1248 Source: CCN Type: AppleCare Knowledge Base Article ID 301596 iTunes 4.8: Security enhancements Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=301596 Source: CCN Type: AppleCare Knowledge Base Article ID 61798 Apple security updates Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2005-05-09 Source: CCN Type: SA15310 iTunes MPEG-4 File Parsing Buffer Overflow Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 15310 Source: CCN Type: SECTRACK ID: 1013927 Apple iTunes MPEG4 Buffer Overflow May Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: Patch, Vendor Advisory 1013927 Source: CCN Type: CIAC INFORMATION BULLETIN P-201 iTunes MPEG4 Parsing Buffer Overflow Source: MISC Type: UNKNOWN http://www.ngssoftware.com/advisories/itunes.txt Source: OSVDB Type: Vendor Advisory 16243 Source: CCN Type: OSVDB ID: 16243 Apple iTunes MPEG-4 File Parsing Overflow Source: BID Type: Patch, Vendor Advisory 13565 Source: CCN Type: BID-13565 Apple iTunes MPEG4 Parsing Buffer Overflow Vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-0504 Source: XF Type: UNKNOWN apple-itunes-mpeg4-bo(20498) Source: XF Type: UNKNOWN apple-itunes-mpeg4-bo(20498) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:17304 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |