CVE-2007-4676

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*

History

No history.

Information

Published : 2007-11-07 23:46

Updated : 2024-02-04 17:13


NVD link : CVE-2007-4676

Mitre link : CVE-2007-4676

CVE.ORG link : CVE-2007-4676


JSON object : View

Products Affected

apple

  • quicktime
  • mac_os_x

microsoft

  • windows_xp
  • windows_vista
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer