CVE-2005-2756: Medium severity QuickTime Player vulnerability
Published Nov 5, 2005
·Updated
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
Affected Software
7 affected components
QuickTime Player<=7.0.2
QuickTime Player=6.5.2
QuickTime Player=6.5.2
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.1
QuickTime Player=7.0.1
Remediation
Patch Available
Event History
Nov 5, 2005
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2756?
CVE-2005-2756 is classified as a high severity vulnerability due to its ability to allow arbitrary code execution.
2
How do I fix CVE-2005-2756?
To fix CVE-2005-2756, upgrade to Apple QuickTime version 7.0.3 or later.
3
What versions of Apple QuickTime are affected by CVE-2005-2756?
CVE-2005-2756 affects Apple QuickTime versions 6.5.2 and 7.0 up to 7.0.2.
4
What type of attack does CVE-2005-2756 involve?
CVE-2005-2756 involves a user-assisted attack where a crafted PICT file triggers a memory overflow.
5
Can CVE-2005-2756 lead to system compromise?
Yes, CVE-2005-2756 can lead to system compromise through arbitrary code execution.