The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Ios | — | Upgrade to the latest version of Apple iOS | Oct 8, 2014 | Sep 20, 2012 |
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2012-004 | Aug 28, 2015 | Sep 20, 2012 |
| Apple Osx Quicktime | — | Apply OS X security update 2012-004Upgrade macOS to the latest version | Sep 27, 2012 | Sep 20, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub