>> Apple Mac OS X Security Update Fixes QuickTime Information Disclosure Vulnerability
Title : Apple Mac OS X Security Update Fixes QuickTime Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2006-5072 CVE ID : CVE-2006-5681
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-12-20
Technical Description
A vulnerability has been identified in Apple Mac OS X, which could be exploited by attackers to gain knowledge of sensitive information. This issue is due to an error in QuickTime for Java when used in conjunction with Quartz Composer to obtain images rendered on screen by embedded QuickTime objects, which could be exploited by malicious Java applets to capture images that may contain local information.