Heap-based Buffer Overflow in Apple QuickTime
CVE-2015-7092

6.6MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
9 January 2016

What is CVE-2015-7092?

Apple QuickTime prior to version 7.7.9 is vulnerable to a heap-based buffer overflow, which can be exploited by attackers through maliciously crafted TXXX frames within ID3 tags in MP3 files. Successful exploitation could lead to arbitrary code execution or denial of service due to application crashes. This vulnerability highlights the importance of keeping software updated to mitigate risks associated with multimedia file processing.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.