PT-2001-1427 · Apple · Quicktime Player Plugin

Published

2001-03-09

·

Updated

2017-12-19

·

CVE-2001-0198

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: QuickTime Player plugin version 4.1.2
Description: The issue allows remote attackers to execute arbitrary commands due to a buffer overflow. This can be triggered via a long HREF parameter in an EMBED tag.
Recommendations: For QuickTime Player plugin version 4.1.2, consider disabling the plugin until a patch is available to prevent exploitation. Avoid using long HREF parameters in EMBED tags to minimize the risk.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0198

Affected Products

Quicktime Player Plugin