Vulnerability Name: | CVE-2005-1579 (CCN-20578) | ||||||||
Assigned: | 2005-05-12 | ||||||||
Published: | 2005-05-12 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: FULLDISC Type: Vendor Advisory 20050511 [DR018] Quartz Composer / QuickTime 7 information leakage Source: MITRE Type: CNA CVE-2005-1579 Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=301714 Source: MLIST Type: Vendor Advisory [quartzcomposer-dev] 20050510 Quartz Quicktime embedded in remote webpages... Source: MLIST Type: Vendor Advisory [quartzcomposer-dev] 20050511 Re: Quartz Quicktime embedded in remote webpages... Source: APPLE Type: UNKNOWN APPLE-SA-2005-05-31 Source: CCN Type: APPLE-SA-2005-05-31 QuickTime 7.0.1 Source: MISC Type: Vendor Advisory http://remahl.se/david/vuln/018 Source: CCN Type: Quartz Composer / QuickTime 7 information leakage information exposuredesign error Source: CCN Type: SA15307 Apple QuickTime Quartz Composer Disclosure of System Information Source: SECUNIA Type: Patch, Vendor Advisory 15307 Source: CCN Type: SECTRACK ID: 1013961 QuickTime Flaw in Processing Quartz Composer Files Lets Remote Users Obtain System Information Source: SECTRACK Type: Vendor Advisory 1013961 Source: CCN Type: QuickTime Web page Apple - QuickTime Source: OSVDB Type: Vendor Advisory 16376 Source: CCN Type: OSVDB ID: 16376 Apple QuickTime Quartz Composer Information Disclosure Source: BID Type: Patch, Vendor Advisory 13603 Source: CCN Type: BID-13603 Apple QuickTime Quartz Composer File Information Disclosure Vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-0531 Source: XF Type: UNKNOWN quicktime-quartz-information-disclosure(20578) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |