vendor:
QuickTime Player
by:
Krystian Kloskowski (h07)
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: QuickTime Player
Affected Version From: 7.3
Affected Version To: 7.3
Patch Exists: NO
Related CWE:
CPE: a:apple:quicktime:7.3
Platforms Tested: Windows XP SP2, Vista
2007
Universal Apple QuickTime Player Exploit
This exploit allows an attacker to gain control over the execution of Apple QuickTime Player by making the buffer larger than the original exploit and overwriting the last exception handler. It has been tested on Apple QuickTime Player 7.3 and 7.2 with Internet Explorer 7, Firefox, and Opera on Windows XP SP2 and Vista.
Mitigation:
Update to a patched version of Apple QuickTime Player.