Vulnerabilities > CVE-2005-3710 - Numeric Errors vulnerability in Apple Quicktime
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows |
NASL id | QUICKTIME_704.NASL |
description | The remote Windows host is running a version of QuickTime prior to 7.0.4. The remote version of QuickTime is vulnerable to various buffer overflows involving specially crafted image and media files. An attacker may be able to leverage these issues to execute arbitrary code on the remote host by sending a malformed file to a victim and have him open it using QuickTime player. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20395 |
published | 2006-01-11 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20395 |
title | QuickTime < 7.0.4 Multiple Vulnerabilities (Windows) |
code |
|
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0440.html
- http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0440.html
- http://docs.info.apple.com/article.html?artnum=303101
- http://docs.info.apple.com/article.html?artnum=303101
- http://secunia.com/advisories/18370
- http://secunia.com/advisories/18370
- http://securityreason.com/securityalert/347
- http://securityreason.com/securityalert/347
- http://securitytracker.com/id?1015465
- http://securitytracker.com/id?1015465
- http://www.kb.cert.org/vuls/id/150753
- http://www.kb.cert.org/vuls/id/150753
- http://www.osvdb.org/22337
- http://www.osvdb.org/22337
- http://www.securityfocus.com/archive/1/421797/100/0/threaded
- http://www.securityfocus.com/archive/1/421797/100/0/threaded
- http://www.securityfocus.com/bid/16202
- http://www.securityfocus.com/bid/16202
- http://www.us-cert.gov/cas/techalerts/TA06-011A.html
- http://www.us-cert.gov/cas/techalerts/TA06-011A.html
- http://www.vupen.com/english/advisories/2006/0128
- http://www.vupen.com/english/advisories/2006/0128
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24059
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24059