CVE-2015-7090: Buffer Overflow
Published Jan 9, 2016
·Updated
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
Affected Software
1 affected component
QuickTime Player<=7.7.8
Event History
Jan 9, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7090?
CVE-2015-7090 is classified as a critical vulnerability that allows remote code execution or denial of service.
2
How do I fix CVE-2015-7090?
To mitigate CVE-2015-7090, update Apple QuickTime to version 7.7.9 or later.
3
What is the impact of CVE-2015-7090?
CVE-2015-7090 can lead to arbitrary code execution or application crashes due to memory corruption.
4
Which versions of Apple QuickTime are affected by CVE-2015-7090?
CVE-2015-7090 affects Apple QuickTime versions prior to 7.7.9.
5
Can CVE-2015-7090 be exploited through a movie file?
Yes, CVE-2015-7090 can be exploited by using a crafted movie file.