Apple QuickTime Panorama Sample Atoms Remote Heap Buffer Overflow Vulnerability

  Severity: CRITICAL
  CVE Identifier: CVE-2007-4675
  Advisory Date: JUL 21, 2015

  DESCRIPTION

Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a QTVR (QuickTime Virtual Reality) movie file containing a large size field in the atom header of a panorama sample atom.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1002526
  Trend Micro Deep Security DPI Rule Name: 1002526 - Apple QuickTime Panorama Sample Atoms Movie File Handling Buffer Overflow

  AFFECTED SOFTWARE AND VERSION

  • Apple Quicktime 7.2