vendor:
Quicktime/Itunes
by:
7.5
CVSS
HIGH
Heap Overflow
CWE
Product Name: Quicktime/Itunes
Affected Version From:
Affected Version To:
Patch Exists:
Related CWE:
CPE:
Platforms Tested:
Quicktime7.5.5/Itunes 8.0 Remote Heap Overflow Crash
The "<? quicktime type= ?>" tag fails to handle long strings, leading to a heap overflow in Quicktime/Itunes media player. This bug can be exploited remotely or locally by supplying a file with a recognized header that does not correspond to the file type. This can be done by embedding XML in a mp4, mov, etc. or in an HTML page, causing a remote crash on browsers using the Quicktime plugin. Code execution may be possible.