CVE-2008-3624: Buffer Overflow
Published Sep 10, 2008
·Updated
Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted panorama atoms.
Affected Software
31 affected components
Apple QuickTime<=7.5
Apple QuickTime=7.0
Apple QuickTime=7.0.1
Apple QuickTime=7.0.2
Apple QuickTime=7.0.3
Apple QuickTime=7.0.4
Apple QuickTime=7.1
Apple QuickTime=7.1.1
Apple QuickTime=7.1.2
Apple QuickTime=7.1.3
Apple QuickTime=7.1.4
Apple QuickTime=7.1.5
Apple QuickTime=7.1.6
Apple QuickTime=7.2
Apple QuickTime=7.3
Apple QuickTime=7.3.1
Apple QuickTime=7.3.1.70
Apple QuickTime=7.4
Apple QuickTime=7.4.1
Apple QuickTime=7.4.5
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.10
Apple iOS and macOS=10.4.11
Apple iOS and macOS=10.5
Apple iOS and macOS=10.5.1
Apple iOS and macOS=10.5.2
Apple iOS and macOS=10.5.3
Apple iOS and macOS=10.5.4
Microsoft Windows-nt=xp-sp3
Microsoft Windows Vista
Microsoft Windows XP=sp2
Event History
Sep 10, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Sep 11, 2008
Data Sourced
01:13 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-3624?
CVE-2008-3624 has been classified as a critical vulnerability due to its potential to allow remote code execution or denial of service.
2
How do I fix CVE-2008-3624?
To fix CVE-2008-3624, update Apple QuickTime to version 7.5.5 or later.
3
What systems are affected by CVE-2008-3624?
CVE-2008-3624 affects various versions of Apple QuickTime prior to 7.5.5.
4
What type of vulnerability is CVE-2008-3624?
CVE-2008-3624 is a heap-based buffer overflow vulnerability.
5
Can CVE-2008-3624 be exploited remotely?
Yes, CVE-2008-3624 can be exploited remotely through specially crafted QuickTime Virtual Reality movie files.