Vulnerabilities > CVE-2004-0926 - Multiple Security vulnerability in Apple Mac OS X
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
Vulnerable Configurations
Nessus
NASL family MacOS X Local Security Checks NASL id MACOSX_SECUPD20040930.NASL description The remote host is missing Security Update 2004-09-30. This security update contains a number of fixes for the following programs : - AFP Server - CUPS - NetInfoManager - postfix - QuickTime - ServerAdmin These programs have multiple vulnerabilities which may allow a remote attacker to execute arbitrary code. last seen 2020-06-01 modified 2020-06-02 plugin id 15420 published 2004-10-04 reporter This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/15420 title Mac OS X Multiple Vulnerabilities (Security Update 2004-09-30) NASL family MacOS X Local Security Checks NASL id MACOSX_QUICKTIME652.NASL description The remote Mac OS X host is running a version of Quicktime that is older than Quicktime 6.5.2. The remote version of this software reportedly fails to check bounds properly when decoding BMP images, leading to a heap overflow. If a remote attacker can trick a user into opening a maliciously crafted BMP file using the affected application, this issue could be leveraged to execute arbitrary code on the affected host. last seen 2020-03-18 modified 2004-10-27 plugin id 15573 published 2004-10-27 reporter This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/15573 title Quicktime < 6.5.2