Lucene search

K
saintSAINT CorporationSAINT:B08C48A11BB65DE96F26A319E0B76B24
HistoryJan 24, 2006 - 12:00 a.m.

QuickTime JPEG buffer overflow

2006-01-2400:00:00
SAINT Corporation
download.saintcorporation.com
11

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.968

Percentile

99.7%

Added: 01/24/2006
CVE: CVE-2005-2340
BID: 16212
OSVDB: 22335

Background

QuickTime is a media player for Windows and Mac OS platforms.

Problem

A buffer overflow in QuickTime allows command execution when a user opens a specially crafted JPEG file.

Resolution

Upgrade to QuickTime 7.0.4 or higher.

References

<http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0392.html&gt;

Limitations

Exploit works on Apple QuickTime PictureViewer 6.5.2. A user must download and open the specially crafted JPEG file in order for exploitation to succeed.

Platforms

Windows

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.968

Percentile

99.7%

Related for SAINT:B08C48A11BB65DE96F26A319E0B76B24