First published: Fri May 11 2012(Updated: )
Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.7.0 | |
Apple iOS and macOS | =10.7.1 | |
Apple iOS and macOS | =10.7.2 | |
Apple macOS Server | =10.7.0 | |
Apple macOS Server | =10.7.1 | |
Apple macOS Server | =10.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0661 has been classified as a high-severity vulnerability due to its potential for remote code execution.
To fix CVE-2012-0661, users should update to Mac OS X 10.7.4 or later.
CVE-2012-0661 affects Mac OS X versions 10.7.0 through 10.7.2.
CVE-2012-0661 can be exploited through crafted movie files that leverage JPEG2000 encoding.
Exploiting CVE-2012-0661 can lead to arbitrary code execution or application crashes.