|
|
| |
| A vulnerability in QuickTime has been discovered which can compromise a user's system. The vulnerability is caused by an error in the parsing of Sorenson Video 3 content. This can be exploited to corrupt memory by tricking a user into viewing a specially crafted movie file. Successful exploitation may allow execution of arbitrary code. |
| |
Credit:
The information has been provided by Carsten Eiram.
The original article can be found at: http://secunia.com/secunia_research/2009-10/
|
| |
Vulnerable Systems:
* Apple QuickTime version 7.60
Immune Systems:
* Apple QuickTime version 7.6.2
CVE Information:
CVE-2009-0188
Disclosure Timeline:
26/02/2009 - Vendor notified.
02/03/200X - Vendor response.
25/05/2009 - Status update requested.
26/05/2009 - Vendor provides status update.
02/06/2009 - Public disclosure.
|
|
|