CVE-2008-0234
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 12.40% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- apple/quicktime
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.htmlPatch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2008/Feb/msg00001.html
- http://secunia.com/advisories/28423Vendor Advisory
- http://secunia.com/advisories/31034Vendor Advisory
- http://securityreason.com/securityalert/3537Exploit
- http://www.kb.cert.org/vuls/id/112179US Government Resource
- http://www.securityfocus.com/archive/1/486091/100/0/threaded
- http://www.securityfocus.com/archive/1/486114/100/0/threaded
- http://www.securityfocus.com/archive/1/486161/100/0/threaded
- http://www.securityfocus.com/archive/1/486174/100/0/threaded
- http://www.securityfocus.com/archive/1/486238/100/0/threaded
- http://www.securityfocus.com/archive/1/486241/100/0/threaded
- http://www.securityfocus.com/archive/1/486268/100/0/threaded
- http://www.securityfocus.com/bid/27225Exploit
- http://www.securitytracker.com/id?1019178
- http://www.vupen.com/english/advisories/2008/0107Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2064/referencesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39601
- https://www.exploit-db.com/exploits/4885
- https://www.exploit-db.com/exploits/4906
- http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.htmlPatch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2008/Feb/msg00001.html
- http://secunia.com/advisories/28423Vendor Advisory
- http://secunia.com/advisories/31034Vendor Advisory
- http://securityreason.com/securityalert/3537Exploit
- http://www.kb.cert.org/vuls/id/112179US Government Resource
- http://www.securityfocus.com/archive/1/486091/100/0/threaded
- http://www.securityfocus.com/archive/1/486114/100/0/threaded
- http://www.securityfocus.com/archive/1/486161/100/0/threaded
- http://www.securityfocus.com/archive/1/486174/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.