Apple QuickTime PICT Parsing Buffer Overflow Vulnerability

ERCOLINO

Membro dello Staff
Amministratore
Registrato
3 Marzo 2003
Messaggi
252.665
Località
Torino
Secunia Advisory: SA35091

Release Date: 2009-05-22


Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched

Software: Apple QuickTime 7.x



Description:
A vulnerability has been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system

The vulnerability is caused due to an error in the processing of "0x77" tags within PICT images, which can be exploited to cause a heap-based buffer overflow when the user opens a specially crafted PICT image or visits a malicious web site.

Solution:
Do not browse untrusted web sites. Do not open files from untrusted sources.


Bollettino Sicurezza
 
Indietro
Alto Basso