>> Apple QuickTime RTSP "Content-Type" Buffer Overflow Vulnerability
Title : Apple QuickTime RTSP "Content-Type" Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-3984 CVE ID : CVE-2007-6166
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-26
Technical Description
A vulnerability has been identified in Apple QuickTime, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by a buffer overflow error when processing an overly long RTSP "Content-Type" header, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into connecting to a specially crafted stream or visiting a malicious web page.