Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://docs.info.apple.com/article.html?artnum=306896 - Vendor Advisory | |
References | () http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.html - Vendor Advisory | |
References | () http://osvdb.org/38546 - Broken Link | |
References | () http://secunia.com/advisories/27523 - Third Party Advisory | |
References | () http://securityreason.com/securityalert/3351 - Third Party Advisory | |
References | () http://www.kb.cert.org/vuls/id/690515 - Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/archive/1/483311/100/0/threaded - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/archive/1/483313/100/0/threaded - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/26345 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id?1018894 - Third Party Advisory, VDB Entry | |
References | () http://www.us-cert.gov/cas/techalerts/TA07-310A.html - Third Party Advisory, US Government Resource | |
References | () http://www.vupen.com/english/advisories/2007/3723 - Third Party Advisory | |
References | () http://www.zerodayinitiative.com/advisories/ZDI-07-066.html - Third Party Advisory, VDB Entry | |
References | () http://www.zerodayinitiative.com/advisories/ZDI-07-067.html - Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/38280 - Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/38281 - Third Party Advisory, VDB Entry |
Information
Published : 2007-11-07 23:46
Updated : 2024-11-21 00:36
NVD link : CVE-2007-4676
Mitre link : CVE-2007-4676
CVE.ORG link : CVE-2007-4676
JSON object : View
Products Affected
apple
- mac_os_x
- quicktime
microsoft
- windows_vista
- windows_xp
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer