CVE-2005-2340: Buffer Overflow
Published Dec 31, 2005
·Updated
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.
Affected Software
4 affected components
QuickTime Player=7.0.1
QuickTime Player=7.0
QuickTime Player=7.0.2
QuickTime Player<=7.0.3
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Jan 11, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2340?
CVE-2005-2340 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2005-2340?
To address CVE-2005-2340, users should upgrade Apple QuickTime to version 7.0.4 or later.
3
What types of files are associated with CVE-2005-2340?
CVE-2005-2340 is associated with QuickTime Image Files (QTIF), PICT, and JPEG format images.
4
What versions of Apple QuickTime are affected by CVE-2005-2340?
CVE-2005-2340 affects Apple QuickTime versions prior to 7.0.4, including 7.0, 7.0.1, 7.0.2, and up to 7.0.3.
5
Can CVE-2005-2340 be exploited remotely?
Yes, CVE-2005-2340 can be exploited remotely through specially crafted image files.