First published: Wed Jan 21 2009(Updated: )
Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=7.5.5 | |
Apple QuickTime | =3.0 | |
Apple QuickTime | =4.1.2 | |
Apple QuickTime | =5.0 | |
Apple QuickTime | =5.0.1 | |
Apple QuickTime | =5.0.2 | |
Apple QuickTime | =6.0 | |
Apple QuickTime | =6.0.0 | |
Apple QuickTime | =6.0.1 | |
Apple QuickTime | =6.0.2 | |
Apple QuickTime | =6.1 | |
Apple QuickTime | =6.1.0 | |
Apple QuickTime | =6.1.1 | |
Apple QuickTime | =6.2.0 | |
Apple QuickTime | =6.3.0 | |
Apple QuickTime | =6.4.0 | |
Apple QuickTime | =6.5 | |
Apple QuickTime | =6.5.0 | |
Apple QuickTime | =6.5.1 | |
Apple QuickTime | =6.5.2 | |
Apple QuickTime | =7.0 | |
Apple QuickTime | =7.0.0 | |
Apple QuickTime | =7.0.1 | |
Apple QuickTime | =7.0.2 | |
Apple QuickTime | =7.0.3 | |
Apple QuickTime | =7.0.4 | |
Apple QuickTime | =7.1 | |
Apple QuickTime | =7.1.0 | |
Apple QuickTime | =7.1.1 | |
Apple QuickTime | =7.1.2 | |
Apple QuickTime | =7.1.3 | |
Apple QuickTime | =7.1.4 | |
Apple QuickTime | =7.1.5 | |
Apple QuickTime | =7.1.6 | |
Apple QuickTime | =7.2 | |
Apple QuickTime | =7.2.1 | |
Apple QuickTime | =7.3 | |
Apple QuickTime | =7.3.0 | |
Apple QuickTime | =7.3.1 | |
Apple QuickTime | =7.3.1.70 | |
Apple QuickTime | =7.4 | |
Apple QuickTime | =7.4.0 | |
Apple QuickTime | =7.4.1 | |
Apple QuickTime | =7.4.5 | |
Apple QuickTime | =7.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0006 has a high severity rating due to the potential for remote attackers to cause denial of service or execute arbitrary code.
To fix CVE-2009-0006, users should update Apple QuickTime to version 7.6 or later.
CVE-2009-0006 affects all Apple QuickTime versions below 7.6, including versions from 3.0 to 7.5.5.
CVE-2009-0006 allows remote attackers to potentially execute arbitrary code and cause application termination through crafted Cinepak encoded movie files.
Using QuickTime versions below 7.6 is unsafe and exposes users to the risks associated with CVE-2009-0006.