CVE-2005-4092

Description

Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and possibly other vectors involving media files. NOTE: item 1 was originally identified by CVE-2005-4127 for a pre-patch announcement, and item 2 was originally identified by CVE-2005-4128 for a pre-patch announcement.

Risk Information

Base Score
7.8
MODERATE
Vector
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
44.088

Associated Vulnerability

VulnerabilityOS Platform
Update Apple iTunes 6.0.2 (x64) to latest versionWindows
Update QuickTime 7.0.4 to latest versionWindows
Multiple Vulnerabilities are affected in Apple iTunes (X64) 6.0.1Windows
Multiple Vulnerabilities are affected in Apple iTunes 6.0.1Windows
Multiple Vulnerabilities are affected in QuickTime 7.0.3Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342817Apple iTunes (X64) (12.13.4.4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234