CVE-2010-3802
Apple QuickTime Panorama Atom Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Integer signedness error in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted panorama atom in a QuickTime Virtual Reality (QTVR) movie file.
Error de presencia de signo (signedness) de entero en Apple QuickTime anterior v7.6.9 permite a atacantes remotos ejecutar código de su elección o causar una denegación de servicio (corrupción de memoria y caída de aplicación) a través de un atom panorama manipulado en un fichero QuickTime Virtual Reality (QTVR)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that a user must be coerced into visiting a malicious page or opening a malicious file.
The specific flaw exists within Apple's support for Panoramic Images and occurs due to the application trusting a particular field for calculation of an offset. Due to the field being treated as a signed integer, the calculated offset can result in a pointer outside the bounds of the expected buffer. Upon usage of this out-of-bounds pointer, the application will write proceed to write image data to the invalid location. Successful exploitation can lead to code execution under the context of the application.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-10-07 CVE Reserved
- 2010-12-07 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/69756 | Vdb Entry | |
http://support.apple.com/kb/HT4581 | X_refsource_confirm | |
http://www.securitytracker.com/id?1024830 | Vdb Entry | |
http://zerodayinitiative.com/advisories/ZDI-10-260 | X_refsource_misc | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16105 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2010//Dec/msg00000.html | 2017-09-19 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html | 2017-09-19 | |
http://support.apple.com/kb/HT4447 | 2017-09-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | <= 7.6.8 Search vendor "Apple" for product "Quicktime" and version " <= 7.6.8" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 3.0 Search vendor "Apple" for product "Quicktime" and version "3.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 4.1.2 Search vendor "Apple" for product "Quicktime" and version "4.1.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 5.0 Search vendor "Apple" for product "Quicktime" and version "5.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 5.0.1 Search vendor "Apple" for product "Quicktime" and version "5.0.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 5.0.2 Search vendor "Apple" for product "Quicktime" and version "5.0.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.0 Search vendor "Apple" for product "Quicktime" and version "6.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.0.0 Search vendor "Apple" for product "Quicktime" and version "6.0.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.0.1 Search vendor "Apple" for product "Quicktime" and version "6.0.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.0.2 Search vendor "Apple" for product "Quicktime" and version "6.0.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.1 Search vendor "Apple" for product "Quicktime" and version "6.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.1.0 Search vendor "Apple" for product "Quicktime" and version "6.1.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.1.1 Search vendor "Apple" for product "Quicktime" and version "6.1.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.2.0 Search vendor "Apple" for product "Quicktime" and version "6.2.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.3.0 Search vendor "Apple" for product "Quicktime" and version "6.3.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.4.0 Search vendor "Apple" for product "Quicktime" and version "6.4.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.5 Search vendor "Apple" for product "Quicktime" and version "6.5" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.5.0 Search vendor "Apple" for product "Quicktime" and version "6.5.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.5.1 Search vendor "Apple" for product "Quicktime" and version "6.5.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 6.5.2 Search vendor "Apple" for product "Quicktime" and version "6.5.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0 Search vendor "Apple" for product "Quicktime" and version "7.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.0 Search vendor "Apple" for product "Quicktime" and version "7.0.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.1 Search vendor "Apple" for product "Quicktime" and version "7.0.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.2 Search vendor "Apple" for product "Quicktime" and version "7.0.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.3 Search vendor "Apple" for product "Quicktime" and version "7.0.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.4 Search vendor "Apple" for product "Quicktime" and version "7.0.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1 Search vendor "Apple" for product "Quicktime" and version "7.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.0 Search vendor "Apple" for product "Quicktime" and version "7.1.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.1 Search vendor "Apple" for product "Quicktime" and version "7.1.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.2 Search vendor "Apple" for product "Quicktime" and version "7.1.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.3 Search vendor "Apple" for product "Quicktime" and version "7.1.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.4 Search vendor "Apple" for product "Quicktime" and version "7.1.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.5 Search vendor "Apple" for product "Quicktime" and version "7.1.5" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.6 Search vendor "Apple" for product "Quicktime" and version "7.1.6" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.2 Search vendor "Apple" for product "Quicktime" and version "7.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.2.1 Search vendor "Apple" for product "Quicktime" and version "7.2.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.3 Search vendor "Apple" for product "Quicktime" and version "7.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.3.0 Search vendor "Apple" for product "Quicktime" and version "7.3.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.3.1 Search vendor "Apple" for product "Quicktime" and version "7.3.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.3.1.70 Search vendor "Apple" for product "Quicktime" and version "7.3.1.70" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.4 Search vendor "Apple" for product "Quicktime" and version "7.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.4.0 Search vendor "Apple" for product "Quicktime" and version "7.4.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.4.1 Search vendor "Apple" for product "Quicktime" and version "7.4.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.4.5 Search vendor "Apple" for product "Quicktime" and version "7.4.5" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.5.0 Search vendor "Apple" for product "Quicktime" and version "7.5.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.5.5 Search vendor "Apple" for product "Quicktime" and version "7.5.5" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.6.0 Search vendor "Apple" for product "Quicktime" and version "7.6.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.6.1 Search vendor "Apple" for product "Quicktime" and version "7.6.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.6.2 Search vendor "Apple" for product "Quicktime" and version "7.6.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.6.5 Search vendor "Apple" for product "Quicktime" and version "7.6.5" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.6.6 Search vendor "Apple" for product "Quicktime" and version "7.6.6" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.6.7 Search vendor "Apple" for product "Quicktime" and version "7.6.7" | - |
Affected
|