Overview
Apple QuickTime is vulnerable to a heap buffer overflow which may allow an attacker to execute arbitrary code or crash the system.
Description
A vulnerability exists in the way Apple QuickTime handles specially crafted QuickTime Image (QTIF) files. According to Apple QuickTime 7.1.5 security document 305149: A heap buffer overflow exists in QuickTime's handling of QTIF files. By enticing a user to access a maliciously-crafted QTIF file, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code or crash the system. |
Solution
Apply an Update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://docs.info.apple.com/article.html?artnum=305149
- http://secunia.com/advisories/24359/
- http://www.auscert.org.au/7356
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=486
- http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=46
- http://www.ciac.org/ciac/bulletins/r-171.shtml
- http://www.securityfocus.com/bid/22827
- http://securitytracker.com/id?1017725
Acknowledgements
This vulnerability was reported by Apple, who in turn credit Ruben Santamarta from iDefense and JJ Reyes for reporting this issue.
This document was written by Katie Steiner.
Other Information
CVE IDs: | CVE-2007-0718 |
Severity Metric: | 17.72 |
Date Public: | 2007-03-06 |
Date First Published: | 2007-03-06 |
Date Last Updated: | 2007-03-19 18:47 UTC |
Document Revision: | 14 |