Attack (Attack ID:319499)

Release Date2010/03/09

Attack NameEXPLOIT Apple QuickTime PICT Image Poly Structure memory corruption -1 (CVE-2007-4676)

Severity

BUG ID

CVE ID

 

Description

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
Impact:Remote code execution
Affected System:Others
Additional References:BID:26345;CVE-2007-4676

 

Solution

Update vendor's patch.