| CVE ID | |
| CVSS SCORE | 6.8, AV:N/AC:M/Au:N/C:P/I:P/A:P |
| AFFECTED VENDORS |
Apple |
| AFFECTED PRODUCTS |
QuickTime |
| VULNERABILITY DETAILS |
The specific flaw exists within the moov atom. By specifying an invalid value for a field within the moov atom, an attacker can write data outside of an allocated heap buffer. An attacker could leverage this to execute arbitrary code under the context of the QuickTime player. |
| ADDITIONAL DETAILS |
11/11/2015 - ZDI reported 2 vulnerabilities to the vendor Vendor Response: https://support.apple.com/HT205771
|
| DISCLOSURE TIMELINE |
|
| CREDIT | Steven Seeley of Source Incite |