Release date:
Updated on:
Affected Systems:
Apple QuickTime Player 7.x
Unaffected system:
Apple QuickTime Player 7.7.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53580
Cve id: CVE-2012-0669
QuickTime is a multimedia architecture developed by Apple Computer. It can process many digital videos, media paragraphs, sound effects, text, animations, music formats, and interactive panoramic images.
A buffer overflow security vulnerability exists in Apple QuickTime 7.7.2 and earlier versions on Windows when processing specially crafted video files encoded by Sorenson. This vulnerability allows remote attackers to execute arbitrary code or cause DOS.
<* Source: Damian Put (pucik@cc-team.org)
Link: http://secunia.com/advisories/47447/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apple
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.apple.com/