Vulnerabilities > CVE-2008-0031 - Resource Management Errors vulnerability in Apple Quicktime
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family MacOS X Local Security Checks NASL id MACOSX_QUICKTIME74.NASL description The version of QuickTime installed on the remote Mac OS X host is older than 7.4. Such versions contain several vulnerabilities that may allow an attacker to execute arbitrary code on the remote host if he can trick the user to open a specially crafted movie or PICT file file with QuickTime. last seen 2020-06-01 modified 2020-06-02 plugin id 29983 published 2008-01-16 reporter This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/29983 title QuickTime < 7.4 Multiple Vulnerabilities (Mac OS X) NASL family Windows NASL id QUICKTIME_74.NASL description The version of QuickTime installed on the remote Windows host is older than 7.4. Such versions contain several vulnerabilities that may allow an attacker to execute arbitrary code on the remote host if he can trick the user to open a specially crafted movie or PICT file file with QuickTime. last seen 2020-06-01 modified 2020-06-02 plugin id 29982 published 2008-01-16 reporter This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/29982 title QuickTime < 7.4 Multiple Vulnerabilities (Windows)
References
- http://docs.info.apple.com/article.html?artnum=307301
- http://docs.info.apple.com/article.html?artnum=307301
- http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html
- http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.html
- http://secunia.com/advisories/28502
- http://secunia.com/advisories/28502
- http://www.securityfocus.com/bid/27298
- http://www.securityfocus.com/bid/27298
- http://www.securitytracker.com/id?1019221
- http://www.securitytracker.com/id?1019221
- http://www.us-cert.gov/cas/techalerts/TA08-016A.html
- http://www.us-cert.gov/cas/techalerts/TA08-016A.html
- http://www.vupen.com/english/advisories/2008/0148
- http://www.vupen.com/english/advisories/2008/0148
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39695
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39695