CVE-2005-2755: Low severity QuickTime Player vulnerability
Published Nov 5, 2005
·Updated
Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.
Affected Software
7 affected components
QuickTime Player<=7.0.2
QuickTime Player=6.5.2
QuickTime Player=6.5.2
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.1
QuickTime Player=7.0.1
Remediation
Patch Available
Event History
Nov 5, 2005
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2755?
CVE-2005-2755 has a severity rating that indicates it could lead to a denial of service due to a crash.
2
How do I fix CVE-2005-2755?
To fix CVE-2005-2755, upgrade to Apple QuickTime Player version 7.0.3 or later.
3
Which versions of Apple QuickTime Player are affected by CVE-2005-2755?
CVE-2005-2755 affects Apple QuickTime Player versions up to and including 7.0.2 and all versions of 6.5.2.
4
Can CVE-2005-2755 be exploited remotely?
CVE-2005-2755 requires user assistance to exploit, typically through a specially crafted media file.
5
What type of attack does CVE-2005-2755 facilitate?
CVE-2005-2755 facilitates a denial of service attack by causing the application to crash through null dereference.