Vulnerability Name:

CVE-2005-1579 (CCN-20578)

Assigned:2005-05-12
Published:2005-05-12
Updated:2011-03-08
Summary:Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: FULLDISC
Type: Vendor Advisory
20050511 [DR018] Quartz Composer / QuickTime 7 information leakage

Source: MITRE
Type: CNA
CVE-2005-1579

Source: CONFIRM
Type: UNKNOWN
http://docs.info.apple.com/article.html?artnum=301714

Source: MLIST
Type: Vendor Advisory
[quartzcomposer-dev] 20050510 Quartz Quicktime embedded in remote webpages...

Source: MLIST
Type: Vendor Advisory
[quartzcomposer-dev] 20050511 Re: Quartz Quicktime embedded in remote webpages...

Source: APPLE
Type: UNKNOWN
APPLE-SA-2005-05-31

Source: CCN
Type: APPLE-SA-2005-05-31
QuickTime 7.0.1

Source: MISC
Type: Vendor Advisory
http://remahl.se/david/vuln/018

Source: CCN
Type: Quartz Composer / QuickTime 7 information leakage
information exposuredesign error

Source: CCN
Type: SA15307
Apple QuickTime Quartz Composer Disclosure of System Information

Source: SECUNIA
Type: Patch, Vendor Advisory
15307

Source: CCN
Type: SECTRACK ID: 1013961
QuickTime Flaw in Processing Quartz Composer Files Lets Remote Users Obtain System Information

Source: SECTRACK
Type: Vendor Advisory
1013961

Source: CCN
Type: QuickTime Web page
Apple - QuickTime

Source: OSVDB
Type: Vendor Advisory
16376

Source: CCN
Type: OSVDB ID: 16376
Apple QuickTime Quartz Composer Information Disclosure

Source: BID
Type: Patch, Vendor Advisory
13603

Source: CCN
Type: BID-13603
Apple QuickTime Quartz Composer File Information Disclosure Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2005-0531

Source: XF
Type: UNKNOWN
quicktime-quartz-information-disclosure(20578)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:apple:quicktime:7.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:apple:quicktime:7.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    apple quicktime 7.0
    apple quicktime 7.0