Release date:
Updated on:
Affected Systems:
Apple Quicktime <7.7.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65787
CVE (CAN) ID: CVE-2014-1251
QuickTime is a multimedia architecture developed by Apple Computer. It can process many digital videos, media paragraphs, sound effects, text, animations, music formats, and interactive panoramic images.
Buffer overflow occurs when processing 'clef' elements in versions earlier than QuickTime 7.7.5 on Windows 7, Vista, and XP SP2. malicious video files can cause unexpected termination of applications or arbitrary code execution.
<* Source: Aliz Hammond
Link: http://support.apple.com/kb/HT6151
Http://secunia.com/advisories/57148/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apple.com/support/downloads/
Http://support.apple.com/kb/HT1338