Summary
The host is running QuickTime Player and is prone to buffer overflow vulnerability.
Impact
Successful exploitation could allow attackers to cause a stack-based buffer overflow by tricking a user into viewing a specially crafted web page that references a SMIL file containing an overly long URL.
Impact Level: Application
Solution
Upgrade to QuickTime Player version 7.6.7 or later For updates refer to http://www.apple.com/quicktime/download/
Insight
The flaw is due to a boundary error in 'QuickTimeStreaming.qtx' when constructing a string to write to a debug log file.
Affected
QuickTime Player version prior to 7.6.7
References
Severity
Classification
-
CVE CVE-2010-1799 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities