CVE-2009-0006: Buffer Overflow
Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0006?
CVE-2009-0006 has a high severity rating due to the potential for remote attackers to cause denial of service or execute arbitrary code.
How do I fix CVE-2009-0006?
To fix CVE-2009-0006, users should update Apple QuickTime to version 7.6 or later.
What versions of Apple QuickTime are affected by CVE-2009-0006?
CVE-2009-0006 affects all Apple QuickTime versions below 7.6, including versions from 3.0 to 7.5.5.
What kind of attack is possible with CVE-2009-0006?
CVE-2009-0006 allows remote attackers to potentially execute arbitrary code and cause application termination through crafted Cinepak encoded movie files.
Is it safe to use QuickTime versions below 7.6 after CVE-2009-0006 has been identified?
Using QuickTime versions below 7.6 is unsafe and exposes users to the risks associated with CVE-2009-0006.