vendor:
QuickTime
by:
Security Explorations
9,3
CVSS
HIGH
Apple QuickTime Java extensions - quicktime.util.QTByteObject initialization security checks bypass
20
CWE
Product Name: QuickTime
Affected Version From: QuickTime 7.7.3
Affected Version To: QuickTime 7.7.4
Patch Exists: YES
Related CWE: CVE-2012-1723
CPE: a:apple:quicktime
Metasploit:
https://www.rapid7.com/db/vulnerabilities/apple-java-cve-2012-1723/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2012-1723/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-1009/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-1019/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2012-1723/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2012-1723/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2012-1723/, https://www.rapid7.com/db/vulnerabilities/jre-vuln-cve-2012-1723/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0729/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0730/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0734/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2012
Apple QuickTime Java extensions – quicktime.util.QTByteObject initialization security checks bypass
This vulnerability allows an attacker to bypass security checks in the initialization of the quicktime.util.QTByteObject class. This can be exploited to execute arbitrary code by loading malicious classes.
Mitigation:
Upgrade to the latest version of QuickTime.