First published: Fri May 24 2013(Updated: )
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=7.7.3 | |
Apple QuickTime | =3.0 | |
Apple QuickTime | =4.1.2 | |
Apple QuickTime | =5.0 | |
Apple QuickTime | =5.0.1 | |
Apple QuickTime | =5.0.2 | |
Apple QuickTime | =6.0 | |
Apple QuickTime | =6.0.0 | |
Apple QuickTime | =6.0.1 | |
Apple QuickTime | =6.0.2 | |
Apple QuickTime | =6.1 | |
Apple QuickTime | =6.1.0 | |
Apple QuickTime | =6.1.1 | |
Apple QuickTime | =6.2.0 | |
Apple QuickTime | =6.3.0 | |
Apple QuickTime | =6.4.0 | |
Apple QuickTime | =6.5 | |
Apple QuickTime | =6.5.0 | |
Apple QuickTime | =6.5.1 | |
Apple QuickTime | =6.5.2 | |
Apple QuickTime | =7.0.0 | |
Apple QuickTime | =7.0.1 | |
Apple QuickTime | =7.0.2 | |
Apple QuickTime | =7.0.3 | |
Apple QuickTime | =7.0.4 | |
Apple QuickTime | =7.1.0 | |
Apple QuickTime | =7.1.1 | |
Apple QuickTime | =7.1.2 | |
Apple QuickTime | =7.1.3 | |
Apple QuickTime | =7.1.4 | |
Apple QuickTime | =7.1.5 | |
Apple QuickTime | =7.1.6 | |
Apple QuickTime | =7.2.0 | |
Apple QuickTime | =7.2.1 | |
Apple QuickTime | =7.3.0 | |
Apple QuickTime | =7.3.1 | |
Apple QuickTime | =7.4.0 | |
Apple QuickTime | =7.4.1 | |
Apple QuickTime | =7.4.5 | |
Apple QuickTime | =7.5.0 | |
Apple QuickTime | =7.5.5 | |
Apple QuickTime | =7.6.0 | |
Apple QuickTime | =7.6.1 | |
Apple QuickTime | =7.6.2 | |
Apple QuickTime | =7.6.5 | |
Apple QuickTime | =7.6.6 | |
Apple QuickTime | =7.6.7 | |
Apple QuickTime | =7.6.8 | |
Apple QuickTime | =7.6.9 | |
Apple QuickTime | =7.7.0 | |
Apple QuickTime | =7.7.1 | |
Apple QuickTime | =7.7.2 | |
Microsoft Windows 7 | ||
Microsoft Windows Vista | ||
Microsoft Windows XP | =sp2 | |
iOS | <=6.1.4 | |
iOS | =1.0.0 | |
iOS | =1.0.1 | |
iOS | =1.0.2 | |
iOS | =1.1.0 | |
iOS | =1.1.1 | |
iOS | =1.1.2 | |
iOS | =1.1.3 | |
iOS | =1.1.4 | |
iOS | =1.1.5 | |
iOS | =2.0 | |
iOS | =2.0.0 | |
iOS | =2.0.1 | |
iOS | =2.0.2 | |
iOS | =2.1 | |
iOS | =2.1.1 | |
iOS | =2.2 | |
iOS | =2.2.1 | |
iOS | =3.0 | |
iOS | =3.0.1 | |
iOS | =3.1 | |
iOS | =3.1.2 | |
iOS | =3.1.3 | |
iOS | =3.2 | |
iOS | =3.2.1 | |
iOS | =3.2.2 | |
iOS | =4.0 | |
iOS | =4.0.1 | |
iOS | =4.0.2 | |
iOS | =4.1 | |
iOS | =4.2.1 | |
iOS | =4.2.5 | |
iOS | =4.2.8 | |
iOS | =4.3.0 | |
iOS | =4.3.1 | |
iOS | =4.3.2 | |
iOS | =4.3.3 | |
iOS | =4.3.5 | |
iOS | =5.0 | |
iOS | =5.0.1 | |
iOS | =5.1 | |
iOS | =5.1.1 | |
iOS | =6.0 | |
iOS | =6.0.1 | |
iOS | =6.0.2 | |
iOS | =6.1 | |
iOS | =6.1.2 | |
iOS | =6.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1019 is classified as a critical vulnerability because it allows remote code execution or denial of service through a buffer overflow.
To fix CVE-2013-1019, you should update Apple QuickTime to version 7.7.4 or later.
Symptoms of CVE-2013-1019 exploitation may include application crashes or unexpected behavior when opening crafted movie files.
CVE-2013-1019 affects all versions of Apple QuickTime prior to 7.7.4 and several older versions including 3.0 to 7.7.3.
CVE-2013-1019 primarily affects users of the Apple QuickTime application across various versions on both iPhone OS and desktop platforms.