Apple QuickTime Remote Integer Overflow Vulnerability
BID:11553
Info
Apple QuickTime Remote Integer Overflow Vulnerability
| Bugtraq ID: | 11553 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0988 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery of this issue is credited to John Heasman of Next Generation Security Software Ltd. |
| Vulnerable: |
Apple QuickTime Player 6.5.1 Apple QuickTime Player 6.5 Apple QuickTime Player 6.1 Apple QuickTime Player 5.0.2 Apple QuickTime Player 6 |
| Not Vulnerable: |
Apple QuickTime Player 6.5.2 |
Discussion
Apple QuickTime Remote Integer Overflow Vulnerability
A remote integer overflow vulnerability affects Apple QuickTime for the Microsoft Windows platform. This issue is due to a failure of the application to properly validate integer signed-ness prior to using it to carry out critical operations.
An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.
A remote integer overflow vulnerability affects Apple QuickTime for the Microsoft Windows platform. This issue is due to a failure of the application to properly validate integer signed-ness prior to using it to carry out critical operations.
An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.
Exploit / POC
Apple QuickTime Remote Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple QuickTime Remote Integer Overflow Vulnerability
Solution:
Apple has released security advisory APPLE-SA-2004-10-27 dealing with this issue. Please see the referenced advisory for more information.
Apple QuickTime Player 6
Apple QuickTime Player 5.0.2
Apple QuickTime Player 6.1
Apple QuickTime Player 6.5
Apple QuickTime Player 6.5.1
Solution:
Apple has released security advisory APPLE-SA-2004-10-27 dealing with this issue. Please see the referenced advisory for more information.
Apple QuickTime Player 6
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
Apple QuickTime Player 5.0.2
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
Apple QuickTime Player 6.1
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
Apple QuickTime Player 6.5
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
Apple QuickTime Player 6.5.1
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
References
Apple QuickTime Remote Integer Overflow Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)
- High Risk Vulnerability in Quicktime for Windows ("NGSSoftware Insight Security Research"
)