CVE-2015-3666: Buffer Overflow
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3667, and CVE-2015-3668.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3666?
CVE-2015-3666 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2015-3666?
To fix CVE-2015-3666, update Apple QuickTime to version 7.7.7 or later, and ensure that your macOS is updated beyond version 10.10.3.
What systems are affected by CVE-2015-3666?
CVE-2015-3666 affects Apple QuickTime version 7.7.6 and macOS versions prior to 10.10.4.
What kind of attack can exploit CVE-2015-3666?
CVE-2015-3666 can be exploited through crafted media files, leading to arbitrary code execution or denial of service.
Is CVE-2015-3666 publicly known?
Yes, CVE-2015-3666 is a publicly documented vulnerability that was disclosed by Apple.