ID

VAR-200209-0001


CVE

CVE-2002-0376


TITLE

Apple QuickTime ActiveX Remote buffer overflow vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200209-047

DESCRIPTION

Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrary code via a long pluginspage field. A vulnerability has been reported in the Apple QuickTime ActiveX component for Internet Explorer. The issue is a buffer-overrun condition that occurs because the software fails to perform adequate boundary checks of supplied arguments. If the component is invoked with the 'pluginspage' argument set to an overly long string value, the overrun will occur. Successful exploits may allow attacker-supplied instructions to run on affected client systems. Apple QuickTime is a media player that provides high-quality sound and images. The Apple QuickTime ActiveX control is generally used for movie tracking and other streaming and static media technology processing when embedded in a WEB page. This control lacks correct checks on the buffer boundary when processing the \"pluginspage\" field, and remote attackers can use it to build malicious WEB pages, or sending HTML emails to entice users to open them, can cause buffer overflows on the client side. Carefully constructed \"pluginspage\" field data may execute arbitrary instructions on the system with the permissions of the current user process

Trust: 1.26

sources: NVD: CVE-2002-0376 // BID: 5685 // VULHUB: VHN-4769

AFFECTED PRODUCTS

vendor:applemodel:quicktimescope:eqversion:5.0.2

Trust: 1.6

vendor:applemodel:quicktime activex componentscope:eqversion:5.0.2

Trust: 0.3

vendor:applemodel:quicktime activex componentscope:neversion:6.0

Trust: 0.3

sources: BID: 5685 // CNNVD: CNNVD-200209-047 // NVD: CVE-2002-0376

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-0376
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200209-047
value: HIGH

Trust: 0.6

VULHUB: VHN-4769
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2002-0376
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-4769
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-4769 // CNNVD: CNNVD-200209-047 // NVD: CVE-2002-0376

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-0376

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200209-047

TYPE

Boundary Condition Error

Trust: 0.9

sources: BID: 5685 // CNNVD: CNNVD-200209-047

EXTERNAL IDS

db:NVDid:CVE-2002-0376

Trust: 2.0

db:BIDid:5685

Trust: 2.0

db:CNNVDid:CNNVD-200209-047

Trust: 0.7

db:BUGTRAQid:20020925 FWD: QUICKTIME FOR WINDOWS ACTIVEX SECURITY ADVISORY

Trust: 0.6

db:XFid:10077

Trust: 0.6

db:ATSTAKEid:A091002-1

Trust: 0.6

db:VULHUBid:VHN-4769

Trust: 0.1

sources: VULHUB: VHN-4769 // BID: 5685 // CNNVD: CNNVD-200209-047 // NVD: CVE-2002-0376

REFERENCES

url:http://www.atstake.com/research/advisories/2002/a091002-1.txt

Trust: 1.7

url:http://www.securityfocus.com/bid/5685

Trust: 1.7

url:http://online.securityfocus.com/archive/1/293095

Trust: 1.7

url:http://www.iss.net/security_center/static/10077.php

Trust: 1.7

sources: VULHUB: VHN-4769 // CNNVD: CNNVD-200209-047 // NVD: CVE-2002-0376

CREDITS

@stake advisories※ advisories@atstake.com

Trust: 0.6

sources: CNNVD: CNNVD-200209-047

SOURCES

db:VULHUBid:VHN-4769
db:BIDid:5685
db:CNNVDid:CNNVD-200209-047
db:NVDid:CVE-2002-0376

LAST UPDATE DATE

2025-04-03T22:19:26.524000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-4769date:2008-09-10T00:00:00
db:BIDid:5685date:2008-03-27T16:19:00
db:CNNVDid:CNNVD-200209-047date:2005-05-13T00:00:00
db:NVDid:CVE-2002-0376date:2025-04-03T01:03:51.193

SOURCES RELEASE DATE

db:VULHUBid:VHN-4769date:2002-09-24T00:00:00
db:BIDid:5685date:2002-09-10T00:00:00
db:CNNVDid:CNNVD-200209-047date:2002-09-24T00:00:00
db:NVDid:CVE-2002-0376date:2002-09-24T04:00:00