Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 08:10:27 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1710254767&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F1008-advisories%2FZDI-10-168.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1710254767.1338192627.1338192627.1338192627.1%3B%2B__utmz%3D32867617.1338192627.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Zero Day Initiative Advisory 10-168 http://packetstormsecurity.org/files/93345/ZDI-10-168.txt http://packetstormsecurity.org/files/93345/ZDI-10-168.txt http://packetstormsecurity.org/files/93345/Zero-Day-Initiative-Advisory-10-168.html Tue, 31 Aug 2010 18:47:29 GMT Zero Day Initiative Advisory 10-168 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the QTPlugin.ocx ActiveX control. The plugin accepts a parameter named _Marshaled_pUnk that it uses as a valid pointer. By specifying invalid values an attacker can force the application to jump to a controlled location in memory. This can be exploited to execute remote code under the context of the user running the web browser.