Vulnerabilities > CVE-2007-0754 - Buffer Overflow vulnerability in Apple QuickTime MOV File STSD Heap

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
apple
critical
nessus

Summary

Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie. This vulnerability is addressed in the following product release: Apple, QuickTime, 7.1.3

Nessus

NASL familyWindows
NASL idQUICKTIME_713.NASL
descriptionThe remote Windows host is running a version of QuickTime prior to 7.1.3. The remote version of QuickTime is vulnerable to various integer and buffer overflows involving specially crafted image and media files. An attacker may be able to leverage these issues to execute arbitrary code on the remote host by sending a malformed file to a victim and having him open it using QuickTime player.
last seen2020-06-01
modified2020-06-02
plugin id22336
published2006-09-13
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/22336
titleQuickTime < 7.1.3 Multiple Vulnerabilities (Windows)