Vulnerabilities > CVE-2004-0431 - Unspecified vulnerability in Apple Quicktime
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN apple
nessus
Summary
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | QUICKTIME_HEAP_OVERFLOW.NASL |
description | The remote host is using QuickTime, a popular media player/Plug-in that handles many Media files. This version has a Heap overflow that could allow an attacker to execute arbitrary code on this host, with the rights of the user running QuickTime. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12226 |
published | 2004-05-05 |
reporter | This script is Copyright (C) 2004-2018 Jeff Adams |
source | https://www.tenable.com/plugins/nessus/12226 |
title | QuickTime < 6.5.1 .mov File sample-to-chunk Table Data Handling Overflow (Windows) |
code |
|
References
- http://lists.apple.com/mhonarc/security-announce/msg00048.html
- http://lists.apple.com/mhonarc/security-announce/msg00048.html
- http://marc.info/?l=bugtraq&m=108360110618389&w=2
- http://marc.info/?l=bugtraq&m=108360110618389&w=2
- http://marc.info/?l=ntbugtraq&m=108356485013237&w=2
- http://marc.info/?l=ntbugtraq&m=108356485013237&w=2
- http://www.kb.cert.org/vuls/id/782958
- http://www.kb.cert.org/vuls/id/782958
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16026
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16026