PT-2008-5417 · Apple · Apple Quicktime+1

Securfrog

·

Published

2008-09-17

·

Updated

2017-09-29

·

CVE-2008-4116

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple QuickTime version 7.5.5 iTunes version 8.0
Description The issue is related to a buffer overflow that can be triggered by a long type attribute in a quicktime tag on a web page or embedded in .mp4 or .mov files. This could lead to a denial of service, causing a browser crash, or possibly allow the execution of arbitrary code. The problem might be connected to the Check stack cookie function and an off-by-one error resulting in a heap-based buffer overflow.
Recommendations For Apple QuickTime version 7.5.5, consider updating to a newer version to mitigate the risk. For iTunes version 8.0, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider restricting the use of quicktime tags in web pages or embedded in .mp4 or .mov files until a patch is available.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4116

Affected Products

Apple Quicktime
Itunes