PT-2008-2622 · Apple · Apple Quicktime

Ruben Santamarta

·

Published

2008-04-04

·

Updated

2018-10-11

·

CVE-2008-1020

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apple QuickTime versions prior to 7.4.5
Description The issue is related to a heap-based buffer overflow in the quickTime.qts component, which can be triggered by a crafted PICT image file with Kodak encoding. This is due to inadequate error checking and error messages. The estimated number of potentially affected devices and details about real-world incidents are not specified.
Recommendations For versions prior to 7.4.5, update to version 7.4.5 or later to resolve the issue.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1020

Affected Products

Apple Quicktime