CVE Vulnerabilities

CVE-2014-1245

Published: Feb 27, 2014 | Modified: Mar 10, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted stsz atom in a movie file.

Affected Software

Name Vendor Start Version End Version
Quicktime Apple 7.6.8 7.6.8
Quicktime Apple 7.3.1 7.3.1
Quicktime Apple 7.6.7 7.6.7
Quicktime Apple 7.69.80.9 7.69.80.9
Quicktime Apple 7.70.80.34 7.70.80.34
Quicktime Apple 7.0.3 7.0.3
Quicktime Apple 7.5.0 7.5.0
Quicktime Apple 7.1.5 7.1.5
Quicktime Apple 7.6.1 7.6.1
Quicktime Apple 7.0.1 7.0.1
Quicktime Apple 7.1.6 7.1.6
Quicktime Apple 7.4.1 7.4.1
Quicktime Apple 7.4.5 7.4.5
Quicktime Apple 7.64.17.73 7.64.17.73
Quicktime Apple 7.6.9 7.6.9
Quicktime Apple 7.7.1 7.7.1
Quicktime Apple 7.2.1 7.2.1
Quicktime Apple 7.0.2 7.0.2
Quicktime Apple 7.67.75.0 7.67.75.0
Quicktime Apple 7.60.92.0 7.60.92.0
Quicktime Apple 7.2.0 7.2.0
Quicktime Apple 7.6.0 7.6.0
Quicktime Apple 7.3.0 7.3.0
Quicktime Apple 7.68.75.0 7.68.75.0
Quicktime Apple 7.0.4 7.0.4
Quicktime Apple 7.3.1.70 7.3.1.70
Quicktime Apple 7.1.2 7.1.2
Quicktime Apple 7.4.0 7.4.0
Quicktime Apple 7.1.1 7.1.1
Quicktime Apple 7.6.6 7.6.6
Quicktime Apple 7.7.2 7.7.2
Quicktime Apple 7.65.17.80 7.65.17.80
Quicktime Apple 7.7.0 7.7.0
Quicktime Apple 7.66.71.0 7.66.71.0
Quicktime Apple 7.1.4 7.1.4
Quicktime Apple 7.1.3 7.1.3
Quicktime Apple * 7.7.4
Quicktime Apple 7.5.5 7.5.5
Quicktime Apple 7.6.2 7.6.2
Quicktime Apple 7.7.3 7.7.3
Quicktime Apple 7.6.5 7.6.5
Quicktime Apple 7.1.0 7.1.0
Quicktime Apple 7.71.80.42 7.71.80.42
Quicktime Apple 7.0.0 7.0.0
Quicktime Apple 7.62.14.0 7.62.14.0

References