Release date:
Updated on:
Affected Systems:
Apple QuickTime Player 7.x
Unaffected system:
Apple QuickTime Player 7.7.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53579
Cve id: CVE-2012-0668
QuickTime is a multimedia architecture developed by Apple Computer. It can process many digital videos, media paragraphs, sound effects, text, animations, music formats, and interactive panoramic images.
A buffer overflow security vulnerability exists in Apple QuickTime 7.7.2 and earlier versions on Windows when processing RLE-encoded special video files. This vulnerability allows remote attackers to execute arbitrary code or cause DOS.
<* Source: Luigi Auriemma (aluigi@pivx.com)
Link: http://secunia.com/advisories/47447/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.apple.com/