-
-
One of the methods exposed allows direct control over low level features of the object, which in turn allows execution of arbitrary code. The code will run with the privileges of the target user opening the PDF document.
Filed under Acrobat Reader¸ Exploit & vulnerability.
-
- February 9, 2008 at 2:35 pm
- March 4, 2008 at 6:00 pm
- 0.3
- url
-
-
-
Apple QuickTime contains a stack buffer overflow vulnerability in the way it handles the RTSP Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocolLive Example
Elia Florio (Symantec) wrap a good introduction post regarding QuickTime 0 day Exploit.
Known Vulnerabilities Proof of concept (milw0rm).
- Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit
- Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 & 7
- Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)
- Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit
Workarounds
You may try the following workarounds [...]
-
- December 6, 2007 at 5:45 pm
- December 26, 2007 at 9:27 pm
- 0.3
- url
-