First published: Wed Sep 10 2008(Updated: )
Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, which triggers heap corruption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=7.5 | |
Apple QuickTime | =7.0 | |
Apple QuickTime | =7.0.1 | |
Apple QuickTime | =7.0.2 | |
Apple QuickTime | =7.0.3 | |
Apple QuickTime | =7.0.4 | |
Apple QuickTime | =7.1 | |
Apple QuickTime | =7.1.1 | |
Apple QuickTime | =7.1.2 | |
Apple QuickTime | =7.1.3 | |
Apple QuickTime | =7.1.4 | |
Apple QuickTime | =7.1.5 | |
Apple QuickTime | =7.1.6 | |
Apple QuickTime | =7.2 | |
Apple QuickTime | =7.3 | |
Apple QuickTime | =7.3.1 | |
Apple QuickTime | =7.3.1.70 | |
Apple QuickTime | =7.4 | |
Apple QuickTime | =7.4.1 | |
Apple QuickTime | =7.4.5 | |
Microsoft Windows NT | =xp-sp3 | |
Microsoft Windows Vista | ||
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-3614 is categorized as high due to the potential for arbitrary code execution.
To fix CVE-2008-3614, upgrade your Apple QuickTime to version 7.5.5 or later.
Exploitation of CVE-2008-3614 can lead to remote code execution or denial of service via application crashes.
CVE-2008-3614 affects all versions of Apple QuickTime prior to 7.5.5.
Yes, CVE-2008-3614 specifically affects Apple QuickTime running on Windows platforms.