KLA10017
Multiple vulnerabilities in Apple QuickTime
Updated: 02/12/2015
CVSS
?
9.3
Detect date
?
05/22/2013
Severity
?
Critical
Description

Multiple serious vulnerabilities have been found in Apple QuickTime. Malicious users can exploit these vulnerabilities to execute arbitrary code or cause denial of service.

Vectors related to unknown applications can be exploited to  execute arbitrary code or cause denial of service via specially designed TeXML, FPX, MP3 or QTIF files; dref, enof or mvhd atoms; or a movie file with H.263, H.264, Sorenson encodings or containing specially designed JPEG data.

 

Affected products

Apple QuickTime versions 7.7.3 and earlier

Solution

Update to latest version
QuickTime

Original advisories

Apple entry

Impacts
?
ACE 
[?]

DoS 
[?]
Related products
Apple QuickTime
CVE-IDS
?

CVE-2013-1020
CVE-2013-1022
CVE-2013-1021
CVE-2013-0986
CVE-2013-0987
CVE-2013-0989
CVE-2013-1018
CVE-2013-1019
CVE-2013-0988
CVE-2013-1016
CVE-2013-1017
CVE-2013-1015