CVE-2009-0956: Critical severity quicktime player vulnerability
Apple QuickTime before 7.6.2 does not properly initialize memory before use in handling movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie containing a user data atom of size zero.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0956?
CVE-2009-0956 is classified as a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2009-0956?
The best way to fix CVE-2009-0956 is to update Apple QuickTime to version 7.6.2 or later.
Which versions of QuickTime are affected by CVE-2009-0956?
CVE-2009-0956 affects Apple QuickTime versions prior to 7.6.2.
What kind of attack can CVE-2009-0956 facilitate?
CVE-2009-0956 can facilitate remote code execution or cause a denial of service due to application crashes.
Is there a known exploit for CVE-2009-0956?
Yes, CVE-2009-0956 has been known to be exploited in the wild due to its ability to handle specially crafted movie files.