Apple.Quicktime.PICT.Opcode.0X8201.Heap

NameApple.Quicktime.PICT.Opcode.0X8201.Heap.Overflow
Release DateJan 07, 2010
SeverityCritical
ImpactSystem compromise or denial of service
DescriptionThis indicates a possible attack against a heap-based buffer-overflow vulnerability in Apple QuickTime.

The vulnerability is due to the way the application parses PICT files. A remote attacker may exploit this by sending a crafted PICT image.
Affected ProductsApple QuickTime before 7.6.2
Recommended ActionsPlease refer to the vendor's advisory for updates or patches:
http://support.apple.com/kb/HT3591
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0953
Reference/shttp://www.securityfocus.com/bid/35164 (BugTraq)
http://www.zerodayinitiative.com/advisories/ZDI-09-027/
Reference: VID-17959