Apple.QuickTime.H264.Integer.Overflow

Alias/esQuickTime.H264.Integer.Overflow
Release DateOct 16, 2006
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against an integer overflow vulnerability in Apple QuickTime.

The vulnerability is caused by insufficient checking of user-supplied input before the vulnerable software copies it to an insufficient buffer. It may allow remote attackers to execute arbitrary code via sending a crafted H.264 movie.
Affected ProductsApple QuickTime Player before 7.1.3
Recommended ActionsApply the most recent upgrades or patches from the vendor:
http://www.apple.com/quicktime/
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-4381
Reference/shttp://www.securityfocus.com/bid/19976 (BugTraq)
Reference: VID-13263