PT-2005-3625 · Apple · Apple Quicktime+1
Dino Dai Zovi
·
Publicado
2005-10-25
·
Atualizado
2008-09-05
·
CVE-2005-2743
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions 10.3.9 and earlier
QuickTime versions 6.52 and earlier
Description
The issue allows untrusted applets to call arbitrary functions in system libraries, which can lead to remote attackers executing arbitrary code. This flaw may result in a loss of integrity and potentially allow malicious users to gain access to unauthorized privileges.
Recommendations
For Mac OS X version 10.3.9 and earlier, consider disabling the Java extensions for QuickTime until a patch is available.
For QuickTime versions 6.52 and earlier, restrict the use of untrusted applets to minimize the risk of exploitation.
As a temporary workaround, consider disabling the ability for applets to call arbitrary functions from within system libraries until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Macos X
Apple Quicktime