[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Apple iTunes Filetype Remote Off-By-One Stack Buffer Overflow Vulnerability

Deprecated
ID: oval:org.mitre.oval:def:6113Date: (C)2008-09-25   (M)2022-10-10
Class: VULNERABILITYFamily: windows




Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file, possibly related to the Check_stack_cookie function and an off-by-one error that leads to a heap-based buffer overflow.

Platform:
Microsoft Windows XP
Microsoft Windows Vista
Product:
Apple iTunes
Reference:
CVE-2008-4116
CVE    1
CVE-2008-4116
CPE    4
cpe:/o:microsoft:windows_xp::sp3:x86
cpe:/o:microsoft:windows_vista:::x86
cpe:/o:microsoft:windows_xp::sp2:x86
cpe:/o:microsoft:windows_vista::sp1:x86
...

© SecPod Technologies