[Full-disclosure] [CIRT.DK] Apple QuickTime 7.0.3 and earlier - JPG/PICT Buffer Overflow

virus at nolog.org virus at nolog.org
Wed Jan 11 16:20:29 GMT 2006


Hello,

CIRT.DK Advisory wrote:
> Apple Quicktime are vulnerable to a buffer overflow in the handling of
> .JPG/.PICT files
> 
> Read the full advisory http://www.cirt.dk/advisories/cirt-41-advisory.pdf

and additional the advisory from Apple, see 
http://lists.apple.com/archives/security-announce/2006/Jan/msg00001.html

Workaround:
Install the newest version, download here:
http://www.apple.com/quicktime/download/standalone.html

GTi




Full-Disclosure is hosted and sponsored by Secunia.