HTTP: Apple QuickTime PICT Poly Underflow

This signature detects attempts to exploit a known vulnerability in Apple QuickTime multimedia player. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.

Extended Description

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.

Short Name
HTTP:STC:IMG:PICT-POLY-UF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Apple CVE-2007-4676 PICT Poly QuickTime Underflow bid:26345
Release Date
11/15/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

9.3

Found a potential security threat?