This Metasploit module exploits a vulnerability found in Apple Quicktime. The flaw is triggered when Quicktime fails to properly handle the data length for certain atoms such as 'rdrf' or 'dref' in the Alis record, which may result a buffer overflow by loading a specially crafted .mov file, and allows arbitrary code execution under the context of the user.
15145b2469bd29030e19b5448ca2e224d6efff120fdd50fb770f210db2a4b736
Apple Security Advisory 2013-05-22-1 - QuickTime 7.7.4 is now available and addresses multiple issues including buffer overflows and arbitrary code execution vulnerabilities.
86bbe08e4962075f0ac3583cedede6a84c05e0fd1931a516233e0cc9267e7b8c