| CVE ID | |
| CVSS SCORE | 6.8, AV:N/AC:M/Au:N/C:P/I:P/A:P |
| AFFECTED VENDORS |
Apple |
| AFFECTED PRODUCTS |
QuickTime |
| VULNERABILITY DETAILS |
The specific flaw exists within atom processing. By providing an invalid index, an attacker can write data outside of an allocated heap buffer. An attacker could leverage this to execute arbitrary code under the context of the QuickTime player. |
| ADDITIONAL DETAILS |
11/11/2015 - ZDI reported 2 vulnerabilities to the vendor Vendor Response: https://support.apple.com/HT205771
|
| DISCLOSURE TIMELINE |
|
| CREDIT | Steven Seeley of Source Incite |