Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Apple QuickTime Multiple vulnerabilities - Dec10 (Windows)

Information

Severity

Severity

Critical

Family

Family

General

CVSSv2 Base

CVSSv2 Base

9.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

13 years ago

Modified

Modified

5 years ago

Summary

The host is running QuickTime Player and is prone to multiple vulnerabilities.

Insight

Insight

The multiple flaws are due to, - A heap overflow error when processing Track Header atoms, which could be exploited to execute arbitrary code via a malicious video or web page. - A filesystem permission error may allow a local user on a Windows system to access the contents of the Apple Computer directory in the user's profile. - A memory corruption error when handling PICT files. - An uninitialized memory access when processing FlashPix images. - A memory corruption error when processing panorama atoms in QTVR (QuickTime Virtual Reality) movie files. - An integer overflow error when processing movie files.

Affected Software

Affected Software

QuickTime Player version prior to 7.6.9

Solution

Solution

Upgrade to QuickTime Player version 7.6.9 or later