Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-4677
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-4677

Description:
Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid color table size when parsing the color table atom (CTAB) in a movie file, related to the CTAB RGB values.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/38283

ST
  1018894

SREASON
  http://securityreason.com/securityalert/3352

SAID
  Secunia Advisory: SA27523

OSVDB
  38544

MISC
  http://www.zerodayinitiative.com/advisories/ZDI-07-065.html

CONFIRM
  http://docs.info.apple.com/article.html?artnum=306896

CERT-VN
  445083

CERT
  http://www.us-cert.gov/cas/techalerts/TA07-310A.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/483312/100/0/threaded

BID
  26338

APPLE
  http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.html


Return to the previous page.