First published: Wed Mar 31 2010(Updated: )
Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample description atom (STSD), and a crafted length value.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=7.6.0 | |
Apple QuickTime | =7.0.0 | |
Apple QuickTime | =7.0.1 | |
Apple QuickTime | =7.0.2 | |
Apple QuickTime | =7.0.3 | |
Apple QuickTime | =7.0.4 | |
Apple QuickTime | =7.1.0 | |
Apple QuickTime | =7.1.1 | |
Apple QuickTime | =7.1.2 | |
Apple QuickTime | =7.1.3 | |
Apple QuickTime | =7.1.4 | |
Apple QuickTime | =7.1.5 | |
Apple QuickTime | =7.1.6 | |
Apple QuickTime | =7.2.0 | |
Apple QuickTime | =7.2.1 | |
Apple QuickTime | =7.3.0 | |
Apple QuickTime | =7.3.1 | |
Apple QuickTime | =7.4.0 | |
Apple QuickTime | =7.4.1 | |
Apple QuickTime | =7.4.5 | |
Apple QuickTime | =7.5.0 | |
Apple QuickTime | =7.5.5 | |
Apple QuickTime | =7.6.1 | |
Apple QuickTime | =7.6.6 | |
Microsoft Windows 7 | ||
Microsoft Windows Vista | ||
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0528 has a high severity as it allows remote attackers to execute arbitrary code or cause a denial of service.
To fix CVE-2010-0528, users should update Apple QuickTime to version 7.6.6 or later on Windows.
CVE-2010-0528 affects Apple QuickTime versions prior to 7.6.6 on Windows.
CVE-2010-0528 may lead to arbitrary code execution or application crashes due to memory corruption.
Yes, after updating to version 7.6.6 or later, it is safe to use QuickTime on Windows regarding CVE-2010-0528.