This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.
The remote Windows host contains an application that may be affected
by multiple vulnerabilities.
The version of QuickTime installed on the remote Windows host is
older than 7.7.3 and therefore is reportedly affected by the
following vulnerabilities :
- A buffer overflow exists in the handling of REGION
records in PICT files. (CVE-2011-1374)
- A memory corruption issue exists in the handling of
PICT files. (CVE-2012-3757)
- A use-after-free issue exists in the QuickTime plugin's
handling of '_qtactivex_' parameters within an HTML
object element. (CVE-2012-3751)
- A buffer overflow exists in the handling of the
transform attribute in text3GTrack elements in TeXML
- Multiple buffer overflows exist in the handling of
style elements in TeXML files. (CVE-2012-3752)
- A buffer overflow exists in the handling of MIME types.
- A use-after-free issue exists in the QuickTime ActiveX
control's handling of the 'Clear()' method.
- A buffer overflow exists in the handling of Targa image
- A buffer overflow exists in the handling of 'rnet'
boxes in MP4 files. (CVE-2012-3756)
Successful exploitation of these issues could result in program
termination or arbitrary code execution, subject to the user's
See also :
Upgrade to QuickTime 7.7.3 or later.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 7.3
Public Exploit Available : true