Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
2007-11-07T23:46:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | quicktime | < 7.3 | No |
Operating System | apple | mac_os_x | 10.3.9 | Yes |
Operating System | apple | mac_os_x | 10.4.10 | Yes |
Operating System | apple | mac_os_x | 10.5 | Yes |
Operating System | microsoft | windows_vista | - | Yes |
Operating System | microsoft | windows_xp | - | Yes |