First published: Sat Dec 31 2005(Updated: )
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=7.0.3 | |
Apple QuickTime | =7.0 | |
Apple QuickTime | =7.0.1 | |
Apple QuickTime | =7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3711 is considered to be of high severity due to the potential for arbitrary code execution.
The recommended fix for CVE-2005-3711 is to upgrade Apple QuickTime to version 7.0.4 or later.
CVE-2005-3711 affects Apple QuickTime versions earlier than 7.0.4, including 7.0, 7.0.1, 7.0.2, and 7.0.3.
Yes, CVE-2005-3711 can be exploited remotely through specially crafted TIFF image files.
CVE-2005-3711 is associated with TIFF image files that have modified StripByteCounts or StripOffsets values.