CVE-2014-1246: Buffer Overflow
Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ftab atom in a movie file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1246?
The severity of CVE-2014-1246 is classified as critical due to the potential for remote code execution and application crash.
How do I fix CVE-2014-1246?
To fix CVE-2014-1246, update Apple QuickTime to version 7.7.5 or later.
What versions of Apple QuickTime are affected by CVE-2014-1246?
CVE-2014-1246 affects Apple QuickTime versions prior to 7.7.5, including all versions from 7.0.0 up to 7.7.4.
What types of attacks can CVE-2014-1246 enable?
CVE-2014-1246 can enable remote attackers to execute arbitrary code or cause a denial of service via malicious movie files.
Is there a workaround for CVE-2014-1246 if I cannot update QuickTime immediately?
There is no documented workaround for CVE-2014-1246 other than to avoid opening untrusted movie files until the vulnerability is patched.