Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value. This vulnerability is addressed in latest version of Quicktime 7.1.5
Publication date: Tue, 06 Mar 2007 04:19:00 +0000