vendor:
QuickTime
by:
David Vaartjes
7.5
CVSS
HIGH
Integer Overflow
Integer Overflow
CWE
Product Name: QuickTime
Affected Version From: QuickTime 7.1.3
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2007-2394
CPE: cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*
Platforms Tested: Windows 2000 SP4
2007
QuickTime SMIL integer overflow vulnerability
This vulnerability can be triggered by luring a target user into running a malicious SMIL file locally or via a webpage. In the later scenario, the OBJECT (IE) and/or EMBED (FireFox) tags can be used. The provided proof of concept code demonstrates the exploit by creating a malicious SMIL file that triggers an integer overflow in QuickTime.
Mitigation:
There is no specific mitigation or remediation mentioned in the text.