漏洞信息详情
Apple QuickTime Quartz Composer文件信息泄露漏洞
- CNNVD编号:CNNVD-200505-1006
- 危害等级: 中危
- CVE编号:
CVE-2005-1579
- 漏洞类型:
设计错误
- 发布时间:
2005-05-12
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
apple - 漏洞来源:
Discovery is credi… -
漏洞简介
Mac OS X 10.4上的Apple QuickTime Player 7.0允许远程攻击者通过一个带有Quartz Composer composition (.qtz)文件(该文件使用特定补丁来读取本地信息,然后用其它补丁发送信息给攻击者)的via a .mov文件来获取敏感信息。
漏洞公告
参考网址
来源: BID
名称: 13603
链接:http://www.securityfocus.com/bid/13603
来源: SECUNIA
名称: 15307
链接:http://secunia.com/advisories/15307
来源: OSVDB
名称: 16376
来源: VUPEN
名称: ADV-2005-0531
链接:http://www.frsirt.com/english/advisories/2005/0531
来源: SECTRACK
名称: 1013961
链接:http://securitytracker.com/id?1013961
来源: MISC
名称: http://remahl.se/david/vuln/018
链接:http://remahl.se/david/vuln/018
来源: APPLE
名称: APPLE-SA-2005-05-31
链接:http://lists.apple.com/archives/security-announce/2005/May/msg00006.html
来源: MLIST
名称: [quartzcomposer-dev] 20050511 Re: Quartz Quicktime embedded in remote webpages…
链接:http://lists.apple.com/archives/quartzcomposer-dev/2005/May/msg00263.html
来源: MLIST
名称: [quartzcomposer-dev] 20050510 Quartz Quicktime embedded in remote webpages…
链接:http://lists.apple.com/archives/quartzcomposer-dev/2005/May/msg00250.html
来源: FULLDISC
名称: 20050511 [DR018] Quartz Composer / QuickTime 7 information leakage
链接:http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0265.html
来源: docs.info.apple.com