CVE-2009-0007: Buffer Overflow
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0007?
CVE-2009-0007 has been rated as a medium severity vulnerability due to its potential to cause a denial of service and possible arbitrary code execution.
How do I fix CVE-2009-0007?
To fix CVE-2009-0007, you should update Apple QuickTime to version 7.6 or later as it addresses this vulnerability.
What types of attacks does CVE-2009-0007 allow?
CVE-2009-0007 can allow attackers to launch denial of service attacks or execute arbitrary code by exploiting malformed QuickTime movie files.
Which versions of Apple QuickTime are affected by CVE-2009-0007?
CVE-2009-0007 affects versions of Apple QuickTime prior to 7.6, including versions 6.0 through 7.5.5.
How was CVE-2009-0007 discovered?
CVE-2009-0007 was discovered through the analysis of the handling of invalid image width data in JPEG atoms within QuickTime movie files.