## https://sploitus.com/exploit?id=SAINT:32367904EF590FCC6E6A788FADB11A13
Added: 08/29/2011
CVE: [CVE-2011-0257](<https://vulners.com/cve/CVE-2011-0257>)
BID: [49144](<http://www.securityfocus.com/bid/49144>)
OSVDB: [74687](<http://www.osvdb.org/74687>)
### Background
[QuickTime](<http://www.apple.com/quicktime/player/>) is a media player for Windows and Mac OS platforms.
### Problem
Apple QuickTime versions prior to 7.7 are vulnerable to a stack overflow cause by improper validation of very large values in the the PnSize field of PICT files.
### Resolution
Upgrade to [Apple QuickTime 7.7](<http://www.apple.com/quicktime/>) or later.
### References
<http://support.apple.com/kb/HT4826>
<http://www.zerodayinitiative.com/advisories/ZDI-11-252/>
### Limitations
This exploit has been tested against Apple QuickTime Player 7.6.9 on Windows XP SP3 English (DEP OptIn).
### Platforms
Windows