CVE-2005-3711: Integer Overflow
Published Dec 31, 2005
·Updated
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values.
Affected Software
4 affected components
QuickTime Player<=7.0.3
QuickTime Player=7.0
QuickTime Player=7.0.1
QuickTime Player=7.0.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Jan 11, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3711?
CVE-2005-3711 is considered to be of high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2005-3711?
The recommended fix for CVE-2005-3711 is to upgrade Apple QuickTime to version 7.0.4 or later.
3
What are the affected versions of Apple QuickTime for CVE-2005-3711?
CVE-2005-3711 affects Apple QuickTime versions earlier than 7.0.4, including 7.0, 7.0.1, 7.0.2, and 7.0.3.
4
Can CVE-2005-3711 be exploited remotely?
Yes, CVE-2005-3711 can be exploited remotely through specially crafted TIFF image files.
5
What types of files are associated with CVE-2005-3711?
CVE-2005-3711 is associated with TIFF image files that have modified StripByteCounts or StripOffsets values.