| Name | Apple.QuickTime.Jpeg2000.Marker.Size.Heap.Overflow |
| Release Date | Jan 21, 2010 |
| Severity | Critical |
| Impact | System compromise or denial of service |
| Description | This indicates a possible attack against a heap-based buffer-overflow vulnerability in Apple QuickTime.
The vulnerability is due to the software's inability to properly parse malformed JP2 images. A remote attacker may exploit this to execute arbitrary code or cause a denial-of-service condition. |
| Affected Products | Apple QuickTime before 7.6.2 |
| Recommended Actions | Please refer to the vendor's advisory for detailed information: http://support.apple.com/kb/HT3591 |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0957
|
| Reference/s | http://www.securityfocus.com/bid/35165 (BugTraq) http://www.zerodayinitiative.com/advisories/ZDI-09-029/
|