CVE-2010-3792: Medium severity Apple QuickTime vulnerability
Published Nov 16, 2010
·Updated
Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.
Affected Software
11 affected components
Apple QuickTime
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.1
Apple iOS and macOS=10.6.2
Apple iOS and macOS=10.6.3
Apple iOS and macOS=10.6.4
Apple Mac OS X Server=10.6.0
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple Mac OS X Server=10.6.3
Apple Mac OS X Server=10.6.4
Remediation
Patch Available
Event History
Nov 16, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
10:00 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-3792?
CVE-2010-3792 has a high severity rating due to its potential to allow remote code execution and application crashes.
2
How do I fix CVE-2010-3792?
To fix CVE-2010-3792, update QuickTime to the latest version available for your Mac OS X system.
3
Which versions of QuickTime are affected by CVE-2010-3792?
CVE-2010-3792 affects QuickTime versions prior to 10.6.5 on Mac OS X 10.6.x.
4
What types of vulnerabilities are associated with CVE-2010-3792?
CVE-2010-3792 involves an integer signedness error that can lead to remote code execution or denial of service.
5
Is there a workaround for CVE-2010-3792 if I cannot update immediately?
While it is recommended to update, a temporary workaround is to avoid opening untrusted MPEG movie files.