CVE-2009-0007Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Quicktime

Severity
9.3CRITICALNVD
EPSS
42.8%
top 2.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 21
Latest updateMay 2

Description

Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDapple/quicktime7.5.5+44

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9gmp-mc2j-jqxr: Heap-based buffer overflow in Apple QuickTime before 72022-05-02
CVEList
CVE-2009-0007: Heap-based buffer overflow in Apple QuickTime before 72009-01-21

💥Exploits & PoCs

2
Exploit-DB
VMware Remote Console e.x.p build-158248 - Format String2010-04-12
Exploit-DB
VMware Player / VMware Workstation 6.5.3 - 'VMware-authd' Remote Denial of Service2009-10-07

💬Community

3
Bugzilla
CVE-2009-0500 moodle: XSS vuln due to missing input validation in logs2009-02-10
Bugzilla
CVE-2008-2368 Certificate System: plain text passwords stored in debug log2008-06-18
Bugzilla
CVE-2008-2367 Certificate System: insecure config file permissions2008-06-18
CVE-2009-0007 — Apple Quicktime vulnerability | cvebase