CVE-2010-3788
Apple QuickTime JP2 SIZ Chunk Uninitialized Object Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 file.
QuickTime en Apple Mac OS X v10.6.x anterior a v10.6.5 accede a memoria sin inicializar durante el procesamiento de datos de imagen JP2 lo que permite a atacantes remotos ejecutar código de su elección o provocar una denegación de servicio (caída de la aplicación) a través de un archivo JP2 manipulado.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the application's support for a component within the SIZ marker in a JPEG 2000 image. When the component contains a malicious value, the application will add a corrupted object to a queue of data which will be processed by the Component Manager's JP2 decompressor. Later when attempting to decompress this data, the application will use the corrupted object. This can lead to code execution under the context of the application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-10-07 CVE Reserved
- 2010-11-10 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://support.apple.com/kb/HT4447 | X_refsource_confirm | |
http://www.securitytracker.com/id?1024729 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://support.apple.com/kb/HT4435 | 2010-12-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.6.0 Search vendor "Apple" for product "Mac Os X" and version "10.6.0" | - |
Affected
| in | Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.6.1 Search vendor "Apple" for product "Mac Os X" and version "10.6.1" | - |
Affected
| in | Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.6.2 Search vendor "Apple" for product "Mac Os X" and version "10.6.2" | - |
Affected
| in | Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.6.3 Search vendor "Apple" for product "Mac Os X" and version "10.6.3" | - |
Affected
| in | Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.6.4 Search vendor "Apple" for product "Mac Os X" and version "10.6.4" | - |
Affected
| in | Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Safe
|
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Server Search vendor "Apple" for product "Mac Os X Server" | 10.6.0 Search vendor "Apple" for product "Mac Os X Server" and version "10.6.0" | - |
Affected
|
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Server Search vendor "Apple" for product "Mac Os X Server" | 10.6.1 Search vendor "Apple" for product "Mac Os X Server" and version "10.6.1" | - |
Affected
|
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Server Search vendor "Apple" for product "Mac Os X Server" | 10.6.2 Search vendor "Apple" for product "Mac Os X Server" and version "10.6.2" | - |
Affected
|
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Server Search vendor "Apple" for product "Mac Os X Server" | 10.6.3 Search vendor "Apple" for product "Mac Os X Server" and version "10.6.3" | - |
Affected
|
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Server Search vendor "Apple" for product "Mac Os X Server" | 10.6.4 Search vendor "Apple" for product "Mac Os X Server" and version "10.6.4" | - |
Affected
|