9.3
CVSSv2

CVE-2008-0234

Published: 11/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions prior to 7.4.1, when RTSP tunneling is enabled, allows remote malicious users to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.

Vulnerable Product Search on Vulmon Subscribe to Product

apple quicktime 7.3.1.70

apple quicktime 7.4

Exploits

Quicktime Player 73170 rtsp Remote Buffer Overflow Exploit PoC githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/4906zip (2008-quicktimebofzip) # milw0rmcom [2008-01-14] ...
####################################################################### Luigi Auriemma Application: Quicktime Player wwwapplecom/quicktime Versions: <= 73170 Platforms: Windows and Mac Bug: buffer-overflow Exploitation: remote Date: 10 Jan 2008 Thanx to: swirl ...