Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-2394
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-2394

Description:
Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/35357

ST
  1018373

SAID
  Secunia Advisory: SA26034

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=556

CONFIRM
  http://docs.info.apple.com/article.html?artnum=305947

CERT
  http://www.us-cert.gov/cas/techalerts/TA07-193A.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/473882/100/100/threaded

BID
  24873

APPLE
  http://lists.apple.com/archives/Security-announce/2007/Jul/msg00001.html


Return to the previous page.