Get a Pentest and security assessment of your IT network.

Advisories

Zero Day Initiative Advisory 10-041

Zero Day Initiative Advisory 10-041 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists during the rendering of an audio stream utilizing QDesign’s audio codec. The application will perform an allocation utilizing a field specified in the sample’s description. Later when initializing the buffer, the application will utilize a different length. If the lengths differ, then a buffer overflow will occur. This can lead to code execution under the context of the currently logged in user.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/87998/ZDI-10-041.txt

Source: https://packetstormsecurity.com/files/87998/Zero-Day-Initiative-Advisory-10-041.html

Related posts
Advisories

Secunia Security Advisory 15017

Advisories

Secunia Security Advisory 18394

Advisories

Secunia Security Advisory 21136

Advisories

Secunia Security Advisory 24114