Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple QuickTime FPX图像文件处理整数溢出漏洞
Vulnerability Description
Apple QuickTime是一款流行的多媒体播放器,支持多种媒体格式。 Apple QuickTime对FlashPix图像文件元素的处理存在整数溢出漏洞,攻击者可能利用此漏洞诱使用户打开恶意文件,在用户机器上执行任意指令或导致进程崩溃。 在FlashPix(fpx)文件中,有一个字段用于指定该文件中存在多少个数据块,如果有一个数据块大小为0x200,QuickTime Player会根据(number*0x200)的计算结果分配内存,但没有检查值的大小,导致整数溢出。如果将块数量的值设置为0x800
CVSS Information
N/A
Vulnerability Type
N/A