Apple QuickTime Apple Video File Image Description Atom Sign Extension Memory Corruption

Strike ID:
E09-6cb01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
t
Variants:
6
Year:
2009

Description

This strike exploits a heap buffer overflow in Apple Quicktime. The vulnerability is due to insuficient validation Clipping Region (CRGN) atoms. An attacker could exploit this vulnerability by enticing a user to open a malicious file with the vulnerable software, potentially executing arbitrary code.

CVE

Bid