Heap-based buffer overflow in Apple QuickTime - CVE-2009-0001
Published: July 21, 2022
Vulnerability identifier: #VU65651
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2009-0001
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in Apple QuickTime. A remote attacker can use a crafted RTSP URL to trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Affected software
Apple QuickTime
IBM PureData System for Operational Analytics
IBM PureData System for Operational Analytics
How to mitigate CVE-2009-0001
Install update from vendor's website.
Apple QuickTime - update to 7.6
External References
- http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html
- http://secunia.com/advisories/33632
- http://support.apple.com/kb/HT3403
- http://www.securityfocus.com/bid/33385
- http://www.us-cert.gov/cas/techalerts/TA09-022A.html
- http://www.vupen.com/english/advisories/2009/0212
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48154
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6135