Heap-based Buffer Overflow in Apple QuickTime Software
CVE-2007-4676
Currently unrated
Key Information:
- Vendor
Apple
- Vendor
- CVE Published:
- 7 November 2007
What is CVE-2007-4676?
A heap-based buffer overflow vulnerability exists in Apple QuickTime versions prior to 7.3. This vulnerability allows remote attackers to execute arbitrary code by sending a specially crafted PICT image containing malformed Poly type (0x0070 to 0x0074) or PackBitsRgn field (0x0099) opcodes. When the QuickTime software parses these elements, it may lead to unintended memory corruption, enabling malicious actions and potential system compromise.