First published: Fri Apr 04 2008(Updated: )
Heap-based buffer overflow in Animation codec content handling in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted movie with run length encoding.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=7.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1021 is classified as a critical vulnerability due to its potential to allow remote arbitrary code execution.
To fix CVE-2008-1021, upgrade Apple QuickTime to version 7.4.5 or later.
CVE-2008-1021 affects Apple QuickTime on Windows versions prior to 7.4.5.
CVE-2008-1021 can be exploited through remote attacks using a specially crafted movie file.
Yes, user interaction is required as the victim must open the malicious movie file for the exploit to succeed.