First published: Fri Apr 04 2008(Updated: )
Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=7.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1013 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
To fix CVE-2008-1013, upgrade Apple QuickTime to version 7.4.5 or later.
CVE-2008-1013 affects Apple QuickTime versions prior to 7.4.5.
CVE-2008-1013 is primarily a remote code execution vulnerability, not directly exploitable by local users.
Attackers exploit CVE-2008-1013 using crafted Java applets that enable the deserialization of QTJava objects.