Required CVE Record Information
Description
Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a QTVR (QuickTime Virtual Reality) movie file containing a large size field in the atom header of a panorama sample atom.
References 13 Total
- us-cert.gov: TA07-310A third-party-advisory
- securityfocus.com: 26342 vdb-entry
- http://www.48bits.com/advisories/qt_pdat_heapbof.pdf
- http://docs.info.apple.com/article.html?artnum=306896
- labs.idefense.com: 20071105 Apple QuickTime Panorama Sample Atom Heap Buffer Overflow Vulnerability third-party-advisory
- securityfocus.com: 20071110 [48Bits Advisory] QuickTime Panorama Sample Atom Heap Overflow mailing-list
- osvdb.org: 38545 vdb-entry
- exchange.xforce.ibmcloud.com: quicktime-qtvr-bo(38282) vdb-entry
- lists.apple.com: APPLE-SA-2007-11-05 vendor-advisory
- http://blog.48bits.com/?p=176
- secunia.com: 27523 third-party-advisory
- securitytracker.com: 1018894 vdb-entry
- vupen.com: ADV-2007-3723 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 13 Total
- us-cert.gov: TA07-310A third-party-advisoryx_transferred
- securityfocus.com: 26342 vdb-entryx_transferred
- http://www.48bits.com/advisories/qt_pdat_heapbof.pdf x_transferred
- http://docs.info.apple.com/article.html?artnum=306896 x_transferred
- labs.idefense.com: 20071105 Apple QuickTime Panorama Sample Atom Heap Buffer Overflow Vulnerability third-party-advisoryx_transferred
- securityfocus.com: 20071110 [48Bits Advisory] QuickTime Panorama Sample Atom Heap Overflow mailing-listx_transferred
- osvdb.org: 38545 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: quicktime-qtvr-bo(38282) vdb-entryx_transferred
- lists.apple.com: APPLE-SA-2007-11-05 vendor-advisoryx_transferred
- http://blog.48bits.com/?p=176 x_transferred
- secunia.com: 27523 third-party-advisoryx_transferred
- securitytracker.com: 1018894 vdb-entryx_transferred
- vupen.com: ADV-2007-3723 vdb-entryx_transferred