Apple QuickTime STSD JPEG Atom Heap Corruption
Severity: CRITICAL
CVE Identifier: CVE-2009-0007
Advisory Date: JUL 21, 2015
DESCRIPTION
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.
TREND MICRO PROTECTION INFORMATION
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1003258
Trend Micro Deep Security DPI Rule Name: 1003258 - Apple QuickTime STSD JPEG Atom Heap Corruption