Published on: 21 August 2015
Multiple vulnerabilities are found in Apple QuickTime. A remote attacker could exploit the vulnerabilities by enticing a user to open a specially crafted media file.
Depending on the vulnerability exploited, a successful attack could lead unexpected application termination, or arbitrary code execution.
Apple QuickTime version 7.7.8 is released to address the issues. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
The new version of QuickTime is available at:
http://www.apple.com/quicktime/download/
https://support.apple.com/en-us/HT205046
https://www.us-cert.gov/ncas/current-activity/2015/08/20/Apple-Releases-Security-Update-QuickTime
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3788 (to CVE-2015-3792)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5751
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5779
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5785
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5786