CVE-2015-7092: Buffer Overflow
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted TXXX frame within an ID3 tag in MP3 data in a movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, and CVE-2015-7117.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7092?
CVE-2015-7092 has a high severity level due to its potential for remote code execution and denial of service.
How do I fix CVE-2015-7092?
To fix CVE-2015-7092, users should upgrade Apple QuickTime to version 7.7.9 or later.
What types of attacks can CVE-2015-7092 enable?
CVE-2015-7092 can enable remote code execution or cause a denial of service through exploitation of a buffer overflow.
Which versions of Apple QuickTime are affected by CVE-2015-7092?
CVE-2015-7092 affects Apple QuickTime versions prior to 7.7.9.
How does CVE-2015-7092 exploit the ID3 tag in MP3 data?
CVE-2015-7092 exploits a crafted TXXX frame within an ID3 tag in MP3 data to trigger the vulnerability.