Release date: 2011-10-28
Updated on: 2011-10-28
Affected Systems:
Apple QuickTime Player 7.x
Unaffected system:
Apple QuickTime Player 7.7.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50101
Cve id: CVE-2011-3223
QuickTime is a multimedia architecture developed by Apple Computer. It can process many digital videos, media paragraphs, sound effects, text, animations, music formats, and interactive panoramic images.
Before Apple QuickTime 10.7.2, a buffer overflow vulnerability exists when processing specially crafted Flic video files. Attackers can exploit this vulnerability to execute arbitrary code with the current user permission, resulting in unexpected application termination.
<* Source: Matt 'j00ru 'Jurczyk
Link: http://support.apple.com/kb/HT5016
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.apple.com/