CVE-2004-0431: Buffer Overflow
Published May 6, 2004
·Updated
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.
Affected Software
1 affected component
QuickTime Player<=6.5
Event History
May 6, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0431?
CVE-2004-0431 is classified as a critical vulnerability due to its potential to allow attackers to execute arbitrary code.
2
How do I fix CVE-2004-0431?
To fix CVE-2004-0431, update Apple QuickTime to version 6.5.1 or later.
3
What type of attack is possible with CVE-2004-0431?
CVE-2004-0431 allows for a heap-based buffer overflow which can lead to arbitrary code execution.
4
Which versions of Apple QuickTime are affected by CVE-2004-0431?
CVE-2004-0431 affects Apple QuickTime versions up to and including 6.5.
5
What is the impact of CVE-2004-0431 on system security?
The impact of CVE-2004-0431 on system security is significant as it enables remote attackers to run malicious code on the victim's system.