Security Advisory

CVE-2010-1818

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-08-31 19:25:00
Last updated 2024-08-07 01:35:53
Assigner apple
State PUBLISHED

Description

The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.