PT-2007-2205 · Apple · Apple Quicktime

Publicado

2007-05-14

·

Atualizado

2018-10-16

·

CVE-2007-0754

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple QuickTime versions prior to 7.1.3
Description A heap-based buffer overflow issue exists due to the failure to validate Sample Table Sample Descriptor (STSD) atoms in QuickTime movies, allowing user-assisted remote attackers to execute arbitrary code via a crafted file. This results in heap corruption and can lead to a loss of integrity.
Recommendations For Apple QuickTime versions prior to 7.1.3, update to version 7.1.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted QuickTime movies that could trigger the heap corruption overflow until a patch is applied. Restrict access to potentially malicious files to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0754

Produtos afetados

Apple Quicktime