CVE-2009-0002Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Quicktime

Severity
9.3CRITICALNVD
EPSS
38.6%
top 2.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 21
Latest updateSep 4

Description

Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDapple/quicktime7.5.5+31

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q2cg-fc43-2qg7: Heap-based buffer overflow in Apple QuickTime before 72022-05-02
CVEList
CVE-2009-0002: Heap-based buffer overflow in Apple QuickTime before 72009-01-21

📋Vendor Advisories

2
Red Hat
kernel: bonding: fix xfrm real_dev null pointer dereference2024-09-04
Red Hat
kernel: RDMA/srp: Set scmnd->result only when scmnd is not NULL2024-05-03
CVE-2009-0002 — Apple Quicktime vulnerability | cvebase