Apple QuickTime < 7.7.9 Multiple Vulnerabilities

critical Nessus Network Monitor Plugin ID 9306

Synopsis

The version of QuickTime on the remote machine is affected by multiple code execution vulnerabilities.

Description

Versions of QuickTime older than 7.7.9 are affected by the following vulnerabilities :

- A flaw is triggered as user-supplied input is not properly validated. With a specially crafted movie file, a context-dependent attacker can corrupt memory and potentially execute arbitrary code. (CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7091)
- A flaw in the 'QuickTime!0x73b390()' function is triggered as user-supplied input is not properly validated when handling dref atoms. With a specially crafted movie file, a context-dependent attacker can trigger an out-of-bounds access and cause a crash, or potentially execute arbitrary code. (CVE-2015-7090)
- An overflow condition is triggered as user-supplied input is not properly validated when handling ID3 version tags in MP3 file. With a specially crafted TXXX frame, a context-dependent attacker can cause a heap-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code. (CVE-2015-7092)
- A flaw is triggered as user-supplied input is not properly validated. With a specially crafted movie file, a context-dependent attacker can corrupt memory and potentially execute arbitrary code. (CVE-2015-7117)

Solution

Upgrade to QuickTime 7.7.9 or later.

See Also

https://support.apple.com/en-us/HT205638

Plugin Details

Severity: Critical

ID: 9306

Family: Web Clients

Published: 4/20/2016

Updated: 3/6/2019

Nessus ID: 87848

Risk Information

VPR

Risk Factor: Medium

Score: 4.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apple:quicktime

Patch Publication Date: 1/7/2016

Vulnerability Publication Date: 1/7/2016

Reference Information

CVE: CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, CVE-2015-7117

BID: 80020, 80170