PT-2005-3625 · Apple · Apple Quicktime+1
Dino Dai Zovi
·
Published
2005-10-25
·
Updated
2008-09-05
·
CVE-2005-2743
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions 10.3.9 and earlier
QuickTime versions 6.52 and earlier
Description
The issue allows untrusted applets to call arbitrary functions in system libraries, which can lead to remote attackers executing arbitrary code. This flaw may result in a loss of integrity and potentially allow malicious users to gain access to unauthorized privileges.
Recommendations
For Mac OS X version 10.3.9 and earlier, consider disabling the Java extensions for QuickTime until a patch is available.
For QuickTime versions 6.52 and earlier, restrict the use of untrusted applets to minimize the risk of exploitation.
As a temporary workaround, consider disabling the ability for applets to call arbitrary functions from within system libraries until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X
Apple Quicktime