CVE-2008-0234: Buffer Overflow
Published Jan 11, 2008
·Updated
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.
Affected Software
2 affected components
QuickTime Player=7.3.1.70
QuickTime Player=7.4
Remediation
Event History
Jan 11, 2008
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0234?
CVE-2008-0234 has been classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2008-0234?
To fix CVE-2008-0234, update Apple QuickTime to version 7.4.1 or later.
3
What versions of Apple QuickTime are affected by CVE-2008-0234?
CVE-2008-0234 affects Apple QuickTime versions 7.3.1.70 and earlier.
4
Can CVE-2008-0234 be exploited remotely?
Yes, CVE-2008-0234 can be exploited remotely through specially crafted RTSP requests.
5
What are the the consequences of CVE-2008-0234 exploitation?
Exploitation of CVE-2008-0234 can allow attackers to execute arbitrary code on the victim's machine.