CVE-2011-0252: Buffer Overflow
Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STTS atoms in a QuickTime movie file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0252?
CVE-2011-0252 has a high severity rating, allowing remote attackers to execute arbitrary code or cause application crashes.
How do I fix CVE-2011-0252?
The fix for CVE-2011-0252 is to update Apple QuickTime to version 7.7 or later.
What impact does CVE-2011-0252 have on systems using vulnerable QuickTime versions?
Systems with vulnerable QuickTime versions can experience remote code execution or denial of service due to heap-based buffer overflow.
How can I determine if my version of Apple QuickTime is affected by CVE-2011-0252?
You can check your Apple QuickTime version against the affected versions listed for CVE-2011-0252, specifically any version prior to 7.7.
What types of attacks could exploit CVE-2011-0252?
Attackers could exploit CVE-2011-0252 using specially crafted QuickTime movie files that contain malicious STTS atoms.