CVE-2011-0209: Integer Overflow
Published Jun 24, 2011
·Updated
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.
Affected Software
22 affected components
All of the following
Apple QuickTime<7.7.0
Any of the following
Apple iOS and macOS<10.6.8
Apple Mac OS X Server<10.6.8
Apple iOS and macOS<10.6.8
Apple iOS and macOS=10.6.7
Apple iOS and macOS=10.6.3
Apple QuickTime
Apple iOS and macOS=10.6.6
Apple iOS and macOS=10.6.1
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.2
Apple iOS and macOS=10.6.4
Apple iOS and macOS=10.6.5
Apple Mac OS X Server=10.6.3
Apple Mac OS X Server=10.6.6
Apple Mac OS X Server=10.6.4
Apple Mac OS X Server=10.6.7
Apple Mac OS X Server=10.6.5
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple Mac OS X Server=10.6.0
Apple QuickTime
Remediation
Patch Available
Event History
Jun 24, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0209?
CVE-2011-0209 is considered a critical vulnerability that can allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2011-0209?
To fix CVE-2011-0209, update your QuickTime and Mac OS X to the latest version as released by Apple.
3
What software is affected by CVE-2011-0209?
CVE-2011-0209 affects multiple versions of Mac OS X prior to 10.6.8 and QuickTime applications.
4
What type of attack can exploit CVE-2011-0209?
CVE-2011-0209 can be exploited through a specially crafted RIFF WAV file, leading to application crashes or arbitrary code execution.
5
Is CVE-2011-0209 only a denial of service vulnerability?
No, while CVE-2011-0209 can cause denial of service, it also allows for remote code execution.