Release date:
Updated on:
Affected Systems:
Apple Quicktime <7.7.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65784
CVE (CAN) ID: CVE-2014-1243
QuickTime is a multimedia architecture developed by Apple Computer. It can process many digital videos, media paragraphs, sound effects, text, animations, music formats, and interactive panoramic images.
The pointer is not initialized when the trail list is processed in versions earlier than QuickTime 7.7.5 on Windows 7, Vista, and XP SP2. a maliciously crafted video file can cause the application to terminate unexpectedly or execute arbitrary code.
<* Source: Tom Gallagher (Microsoft)
Paul Bates (Microsoft)
Link: http://support.apple.com/kb/HT6151
Http://secunia.com/advisories/57148/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apple.com/support/downloads/
Http://support.apple.com/kb/HT1338