CVE-2007-0462
published 2007-01-26CVE-2007-0462: The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
6.60%
93.1th percentile
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | quicktime | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mj44-3pg8-598c: The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2007-0588 [CRITICAL] GHSA-mj44-3pg8-598c: The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7
The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462.
GHSA
GHSA-7rwm-m7c5-7p3g: The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7
ghsa_unreviewed·2022-05-01
CVE-2007-0462 [HIGH] GHSA-7rwm-m7c5-7p3g: The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.
No detection rules found.
No writeups or analysis indexed.
http://projects.info-pull.com/moab/MOAB-23-01-2007.htmlhttp://secunia.com/advisories/23859http://www.osvdb.org/32696http://www.securityfocus.com/bid/22207http://www.vupen.com/english/advisories/2007/0337https://exchange.xforce.ibmcloud.com/vulnerabilities/31698http://projects.info-pull.com/moab/MOAB-23-01-2007.htmlhttp://secunia.com/advisories/23859http://www.osvdb.org/32696http://www.securityfocus.com/bid/22207http://www.vupen.com/english/advisories/2007/0337https://exchange.xforce.ibmcloud.com/vulnerabilities/31698
2007-01-26
Published