This application requires Javascript for optimal performance.

Apple.QuickTime.Jpeg2000.Marker.Size.Heap.Overflow

Release Date

Jan 21, 2010

Severity

critical

Impact

System compromise or denial of service

Description

This indicates a possible attack against a heap-based buffer-overflow vulnerability in Apple QuickTime.

The vulnerability is due to the software's inability to properly parse malformed JP2 images. A remote attacker may exploit this to execute arbitrary code or cause a denial-of-service condition.

Affected Products

Apple QuickTime before 7.6.2

Recommended Actions

Please refer to the vendor's advisory for detailed information:
http://support.apple.com/kb/HT3591

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-0957

Reference/s

http://www.zerodayinitiative.com/advisories/ZDI-09-029/
http://www.securityfocus.com/bid/35165 (BugTraq)

Reference: VID-17961