CVE-2005-3710: Integer Overflow
Published Dec 31, 2005
·Updated
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags.
Affected Software
4 affected components
QuickTime Player<=7.0.3
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Jan 11, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3710?
CVE-2005-3710 is classified as a medium severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2005-3710?
To fix CVE-2005-3710, you should update Apple QuickTime to version 7.0.4 or later.
3
What software versions are affected by CVE-2005-3710?
CVE-2005-3710 affects Apple QuickTime versions 7.0.1, 7.0.2, 7.0.3, and 7.0.
4
What type of attack is possible with CVE-2005-3710?
CVE-2005-3710 allows attackers to execute arbitrary code by exploiting an integer overflow through specially crafted TIFF image files.
5
Is CVE-2005-3710 a client-side or server-side vulnerability?
CVE-2005-3710 is primarily a client-side vulnerability that affects users of Apple QuickTime when processing manipulated TIFF images.