vendor:
Motion
by:
Jean Pascal Pereira
9,3
CVSS
HIGH
Integer Overflow
190
CWE
Product Name: Motion
Affected Version From: Motion 5.0.7
Affected Version To: Motion 5.0.7
Patch Exists: YES
Related CWE: CVE-2013-5134
CPE: a:apple:motion:5.0.7
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OS X 10.8
2013
Apple Motion Integer Overflow Vulnerability
An integer overflow vulnerability has been identified in Apple Motion. The issue has been verified for Motion 5.0.7 (current release). Prior versions may also be affected. An attacker has the possibility to provide a crafted .motn file containing a viewer element with a subview attribute. If the subview attribute is set to a very low or high integer value, the application crashes due an access violation.
Mitigation:
Upgrade to the latest version of Motion