CVE-2008-0234
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.
- Affected products
- Quicktime Player
- Apple Quicktime
- = 7.3.1.70, 7.4
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 12.4% (96th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2008-01-11
CVE-2008-0234 at NVD
2 known exploits for CVE-2008-0234
Proof-of-concept code and exploit modules indexed by Sploitus