CVE-2009-0955: Code Injection
Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image description atoms in an Apple video file, related to a "sign extension issue."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0955?
CVE-2009-0955 is classified as a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2009-0955?
To fix CVE-2009-0955, users should update Apple QuickTime to version 7.6.2 or later.
What type of vulnerability is CVE-2009-0955?
CVE-2009-0955 is a vulnerability that allows for remote code execution through specially crafted Apple video files.
Which versions of Apple QuickTime are affected by CVE-2009-0955?
CVE-2009-0955 affects multiple versions of Apple QuickTime, including versions 5.0.1 to 7.5.5.
What are the potential impacts of CVE-2009-0955?
The potential impacts of CVE-2009-0955 include arbitrary code execution and application crashes due to a denial of service.