RULE(RULE ID:305297)

Rule General Information
Release Date: 2015-12-21
Rule Name: Apple Quicktime Qtplugin.ocx _marshaled_punk Code Execution Vulnerability -1 (CVE-2010-1818)
Severity:
CVE ID:
Rule Protection Details
Description: The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshaling of an untrusted pointer.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: http://lists.apple.com/archives/security-announce/2010/Sep/msg00003.html
http://reversemode.com/index.php?option=com_content&task=view&id=69&Itemid=1
http://support.apple.com/kb/ht4339
Solutions
Upgrade to version 7.6.7 to solve the problem.