CVE-2008-3614: Integer Overflow
Published Sep 10, 2008
·Updated
Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, which triggers heap corruption.
Affected Software
23 affected components
Apple Quicktime<=7.5
Apple Quicktime=7.0
Apple Quicktime=7.0.1
Apple Quicktime=7.0.2
Apple Quicktime=7.0.3
Apple Quicktime=7.0.4
Apple Quicktime=7.1
Apple Quicktime=7.1.1
Apple Quicktime=7.1.2
Apple Quicktime=7.1.3
Apple Quicktime=7.1.4
Apple Quicktime=7.1.5
Apple Quicktime=7.1.6
Apple Quicktime=7.2
Apple Quicktime=7.3
Apple Quicktime=7.3.1
Apple Quicktime=7.3.1.70
Apple Quicktime=7.4
Apple Quicktime=7.4.1
Apple Quicktime=7.4.5
Microsoft Windows-nt=xp-sp3
Microsoft Windows Vista
Microsoft Windows XP=sp2
Event History
Sep 10, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Sep 11, 2008
Data Sourced
01:13 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-3614?
The severity of CVE-2008-3614 is categorized as high due to the potential for arbitrary code execution.
2
How do I fix CVE-2008-3614?
To fix CVE-2008-3614, upgrade your Apple QuickTime to version 7.5.5 or later.
3
What types of attacks are possible due to CVE-2008-3614?
Exploitation of CVE-2008-3614 can lead to remote code execution or denial of service via application crashes.
4
What versions of Apple QuickTime are affected by CVE-2008-3614?
CVE-2008-3614 affects all versions of Apple QuickTime prior to 7.5.5.
5
Is CVE-2008-3614 specific to Apple QuickTime on Windows?
Yes, CVE-2008-3614 specifically affects Apple QuickTime running on Windows platforms.