First published: Thu Feb 27 2014(Updated: )
Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted clef atom in a movie file.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple QuickTime | <=7.7.4 | |
Apple QuickTime | =7.0.0 | |
Apple QuickTime | =7.0.1 | |
Apple QuickTime | =7.0.2 | |
Apple QuickTime | =7.0.3 | |
Apple QuickTime | =7.0.4 | |
Apple QuickTime | =7.1.0 | |
Apple QuickTime | =7.1.1 | |
Apple QuickTime | =7.1.2 | |
Apple QuickTime | =7.1.3 | |
Apple QuickTime | =7.1.4 | |
Apple QuickTime | =7.1.5 | |
Apple QuickTime | =7.1.6 | |
Apple QuickTime | =7.2.0 | |
Apple QuickTime | =7.2.1 | |
Apple QuickTime | =7.3.0 | |
Apple QuickTime | =7.3.1 | |
Apple QuickTime | =7.3.1.70 | |
Apple QuickTime | =7.4.0 | |
Apple QuickTime | =7.4.1 | |
Apple QuickTime | =7.4.5 | |
Apple QuickTime | =7.5.0 | |
Apple QuickTime | =7.5.5 | |
Apple QuickTime | =7.6.0 | |
Apple QuickTime | =7.6.1 | |
Apple QuickTime | =7.6.2 | |
Apple QuickTime | =7.6.5 | |
Apple QuickTime | =7.6.6 | |
Apple QuickTime | =7.6.7 | |
Apple QuickTime | =7.6.8 | |
Apple QuickTime | =7.6.9 | |
Apple QuickTime | =7.7.0 | |
Apple QuickTime | =7.7.1 | |
Apple QuickTime | =7.7.2 | |
Apple QuickTime | =7.7.3 | |
Apple QuickTime | =7.60.92.0 | |
Apple QuickTime | =7.62.14.0 | |
Apple QuickTime | =7.64.17.73 | |
Apple QuickTime | =7.65.17.80 | |
Apple QuickTime | =7.66.71.0 | |
Apple QuickTime | =7.67.75.0 | |
Apple QuickTime | =7.68.75.0 | |
Apple QuickTime | =7.69.80.9 | |
Apple QuickTime | =7.70.80.34 | |
Apple QuickTime | =7.71.80.42 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1251 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2014-1251, you should update Apple QuickTime to version 7.7.5 or later.
CVE-2014-1251 affects Apple QuickTime versions 7.7.4 and earlier.
CVE-2014-1251 can be exploited to carry out remote code execution or cause an application crash.
If you cannot update QuickTime, consider disabling it or avoiding the use of untrusted movie files.