Severity: : Critical
  CVE Kennungen: : CVE-2007-4675
  Advisory Date: 21 de lipca de 2015

  DESCRIPTION

Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a QTVR (QuickTime Virtual Reality) movie file containing a large size field in the atom header of a panorama sample atom.

  INFORMATION EXPOSURE

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1002526
  Trend Micro Deep Security DPI Rule Name: 1002526 - Apple QuickTime Panorama Sample Atoms Movie File Handling Buffer Overflow

  AFFECTED SOFTWARE AND VERSION:

  • Apple Quicktime 7.2