CVE-2007-4676
Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 46.66% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- apple/mac os x · microsoft/windows vista · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=306896Vendor Advisory
- http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.htmlVendor Advisory
- http://osvdb.org/38546Broken Link
- http://secunia.com/advisories/27523Third Party Advisory
- http://securityreason.com/securityalert/3351Third Party Advisory
- http://www.kb.cert.org/vuls/id/690515Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/483311/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/483313/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/26345Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018894Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-310A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/3723Third Party Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-066.htmlThird Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-07-067.htmlThird Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38280Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38281Third Party Advisory, VDB Entry
- http://docs.info.apple.com/article.html?artnum=306896Vendor Advisory
- http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.htmlVendor Advisory
- http://osvdb.org/38546Broken Link
- http://secunia.com/advisories/27523Third Party Advisory
- http://securityreason.com/securityalert/3351Third Party Advisory
- http://www.kb.cert.org/vuls/id/690515Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/483311/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/483313/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/26345Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018894Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-310A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/3723Third Party Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-066.htmlThird Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-07-067.htmlThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.