CVE-2008-3629: Medium severity quicktime player vulnerability
Published Sep 10, 2008
·Updated
Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read.
Affected Software
37 affected components
Apple QuickTime<=7.5
Apple QuickTime=7.0
Apple QuickTime=7.0.1
Apple QuickTime=7.0.2
Apple QuickTime=7.0.3
Apple QuickTime=7.0.4
Apple QuickTime=7.1
Apple QuickTime=7.1.1
Apple QuickTime=7.1.2
Apple QuickTime=7.1.3
Apple QuickTime=7.1.4
Apple QuickTime=7.1.5
Apple QuickTime=7.1.6
Apple QuickTime=7.2
Apple QuickTime=7.3
Apple QuickTime=7.3.1
Apple QuickTime=7.3.1.70
Apple QuickTime=7.4
Apple QuickTime=7.4.1
Apple QuickTime=7.4.5
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.10
Apple iOS and macOS=10.4.11
Apple iOS and macOS=10.5
Apple iOS and macOS=10.5.1
Apple iOS and macOS=10.5.2
Apple iOS and macOS=10.5.3
Apple iOS and macOS=10.5.4
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.4.9
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.11
Apple Mac OS X Server=10.5
Microsoft Windows-nt=xp-sp3
Microsoft Windows Vista
Microsoft Windows XP=sp2
Remediation
Event History
Sep 10, 2008
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Sep 11, 2008
Data Sourced
01:13 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-3629?
CVE-2008-3629 has been classified as a denial of service vulnerability that could cause application crashes.
2
How do I fix CVE-2008-3629?
To mitigate CVE-2008-3629, it is recommended to update Apple QuickTime to version 7.5.5 or later.
3
What versions of QuickTime are affected by CVE-2008-3629?
CVE-2008-3629 affects Apple QuickTime versions prior to 7.5.5, including all 7.x versions leading up to 7.5.
4
Can CVE-2008-3629 be exploited remotely?
Yes, CVE-2008-3629 can be exploited remotely by sending a specially crafted PICT image to the target.
5
What are the potential impacts of CVE-2008-3629?
The exploitation of CVE-2008-3629 can result in denial of service, causing the QuickTime application to crash.