Apple QuickTime Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to disclose sensitive information or take complete control of an affected system. These issues are caused by memory corruption and implementation errors when processing specially crafted Java applets, data reference atoms, movie media tracks, movie files with Animation codec, "crgn" and "chan" atoms, records, Clip opcode and error messages within PICT images, and "obji" atoms in VR movie files, which could be exploited by remote attackers to gain knowledge of sensitive information or execute arbitrary code by tricking a user into visiting a malicious web page.
Impact
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Apple QuickTime versions prior to 7.4.5
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Update to the fixed version:
Apple QuickTime 7.4.5 for Windows :
http://www.apple.com/support/downloads/quicktime745forwindows.htmlApple QuickTime 7.4.5 for Leopard :
http://www.apple.com/support/downloads/quicktime745forleopard.htmlApple QuickTime 7.4.5 for Panther :
http://www.apple.com/support/downloads/quicktime745forpanther.htmlApple QuickTime 7.4.5 for Tiger :
http://www.apple.com/support/downloads/quicktime745fortiger.html
Vulnerability Identifier
- CVE-2008-1013
- CVE-2008-1014
- CVE-2008-1015
- CVE-2008-1016
- CVE-2008-1017
- CVE-2008-1018
- CVE-2008-1019
- CVE-2008-1020
- CVE-2008-1021
- CVE-2008-1022
- CVE-2008-1023
Source
Related Link
Share with