First published: Thu May 06 2004(Updated: )
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0431 is classified as a critical vulnerability due to its potential to allow attackers to execute arbitrary code.
To fix CVE-2004-0431, update Apple QuickTime to version 6.5.1 or later.
CVE-2004-0431 allows for a heap-based buffer overflow which can lead to arbitrary code execution.
CVE-2004-0431 affects Apple QuickTime versions up to and including 6.5.
The impact of CVE-2004-0431 on system security is significant as it enables remote attackers to run malicious code on the victim's system.