Heap-based buffer overflow in macOS and macOS Server - CVE-2011-3448
Published: February 2, 2012 / Updated: August 11, 2020
macOS
macOS Server
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3. A remote attacker can use a crafted movie file with H.264 encoding. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.