vendor:
QuickTime
by:
David Vaartjes
7.5
CVSS
HIGH
Information Disclosure, Remote Code Execution
Integer Overflow
CWE
Product Name: QuickTime
Affected Version From: All versions of QuickTime prior to 7.1.3
Affected Version To: 7.1.2003
Patch Exists: NO
Related CWE: CVE-2007-2394
CPE: a:apple:quicktime:7.1.3
Platforms Tested: Windows 2000 SP4
2007
Apple QuickTime Information Disclosure and Remote Code Execution Vulnerabilities
Remote attackers can exploit these vulnerabilities by enticing victims into opening maliciously crafted files or visiting maliciously crafted websites. Successful exploits may allow attackers to execute arbitrary code in the context of a user running the vulnerable application or to obtain sensitive information. Failed exploit attempts of remote code-execution issues may result in denial-of-service conditions. Successful exploits of the information-disclosure issue may lead to further attacks.
Mitigation:
Update to the latest version of QuickTime. Do not open or download files from untrusted sources.