Vulnerability Description
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Easy Software Products | Cups | 1.0.4 |
| Apple | Mac Os X | 10.2 |
| Apple | Mac Os X Server | 10.2 |
References
- http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.htmlPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html
- http://www.securityfocus.com/bid/11322PatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.htmlPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html
- http://www.securityfocus.com/bid/11322PatchVendor Advisory
FAQ
What is CVE-2004-0926?
CVE-2004-0926 is a vulnerability with a CVSS score of 10.0 (HIGH). Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
How severe is CVE-2004-0926?
CVE-2004-0926 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0926?
Check the references section above for vendor advisories and patch information. Affected products include: Easy Software Products Cups, Apple Mac Os X, Apple Mac Os X Server.