Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an incorrect buffer length calculation.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Coremedia | — | Upgrade macOS to the latest version | Dec 16, 2011 | Mar 30, 2010 |
| Apple Osx Quicktime | — | Upgrade macOS to the latest version | Dec 16, 2011 | Mar 30, 2010 |
| Quicktime | — | Upgrade to Apple QuickTime version 7.6.6 | Oct 25, 2010 | Mar 30, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub