Apple Mac OS X QuickTime contains a uninitialized memory location access issue that may allow a context-dependent attacker to execute arbitrary code or cause a denial of service. The issue is triggered when viewing a maliciously crafted GIF image and the program not handlnig LZW descompression correctly.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade to version 10.6.5 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.