This application requires Javascript for optimal performance.

Apple.QuickTime.H264.Integer.Overflow

Alias(es)

QuickTime.H264.Integer.Overflow

Release Date

Oct 16, 2006

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against an integer overflow vulnerability in Apple QuickTime.

The vulnerability is caused by insufficient checking of user-supplied input before the vulnerable software copies it to an insufficient buffer. It may allow remote attackers to execute arbitrary code via sending a crafted H.264 movie.

Affected Products

Apple QuickTime Player before 7.1.3

Recommended Actions

Apply the most recent upgrades or patches from the vendor:
http://www.apple.com/quicktime/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-4381

Reference/s

http://www.securityfocus.com/bid/19976 (BugTraq)

Reference: VID-13263