Apple QuickTime Embedded Pascal Style Remote Integer Overflow Vulnerability
BID:15306
Info
Apple QuickTime Embedded Pascal Style Remote Integer Overflow Vulnerability
| Bugtraq ID: | 15306 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2753 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2005 12:00AM |
| Updated: | Nov 03 2005 12:00AM |
| Credit: | Piotr Bania <[email protected]> reported this issue to the vendor. |
| Vulnerable: |
Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 6.5.2 Apple QuickTime Player 6.5.1 Apple QuickTime Player 6.5 Apple QuickTime Player 6.1 Apple QuickTime Player 5.0.2 Apple QuickTime Player 6 |
| Not Vulnerable: |
Apple QuickTime Player 7.0.3 |
Discussion
Apple QuickTime Embedded Pascal Style Remote Integer Overflow Vulnerability
A remote integer overflow vulnerability affects Apple QuickTime. This issue is due to a failure of the application to properly validate integer signed-ness prior to using it to carry out critical operations.
An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.
This issue affects both Microsoft Windows, and Apple versions of QuickTime.
A remote integer overflow vulnerability affects Apple QuickTime. This issue is due to a failure of the application to properly validate integer signed-ness prior to using it to carry out critical operations.
An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.
This issue affects both Microsoft Windows, and Apple versions of QuickTime.
Exploit / POC
Apple QuickTime Embedded Pascal Style Remote Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple QuickTime Embedded Pascal Style Remote Integer Overflow Vulnerability
Solution:
Apple has released version 7.0.3 of QuickTime to address this, and other issues. Users are encouraged to utilize the built-in 'Software Update' feature to download and install fixes. Please see the referenced Apple document for further information.
Apple QuickTime Player 6
Apple QuickTime Player 5.0.2
Apple QuickTime Player 6.1
Apple QuickTime Player 6.5
Apple QuickTime Player 6.5.1
Apple QuickTime Player 6.5.2
Apple QuickTime Player 7.0
Apple QuickTime Player 7.0.1
Apple QuickTime Player 7.0.2
Solution:
Apple has released version 7.0.3 of QuickTime to address this, and other issues. Users are encouraged to utilize the built-in 'Software Update' feature to download and install fixes. Please see the referenced Apple document for further information.
Apple QuickTime Player 6
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 5.0.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
References
Apple QuickTime Embedded Pascal Style Remote Integer Overflow Vulnerability
References:
References:
- About the security content of QuickTime 7.0.3 (Apple)
- Apple QuickTime Homepage (Apple)
- Apple Security Updates (Apple)
- Advisory: Apple QuickTime Player Remote Integer Overflow (1) (Piotr Bania
)