Intrusion Prevention

Apple.QuickTime.RTSP.URI.Handling.Remote.Command.Execution

Description

This indicates an attack attempt against a Buffer Overflow vulnerability in Apple QuickTime.
The vulnerability is caused by an error when the software handles a malformed "rtsp" URI. It allows a remote attacker to execute arbitrary code via a malicious QTL file.

Affected Products

Apple QuickTime version 7.1.3 and prior.
Apple iTunes version 7.0.2 and prior.

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the patch, available from the website:
http://docs.info.apple.com/article.html?artnum=304989

CVE References

CVE-2007-0015