Apple QuickTime Null Pointer Dereference Denial of Service Vulnerability
BID:15307
Info
Apple QuickTime Null Pointer Dereference Denial of Service Vulnerability
| Bugtraq ID: | 15307 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-2755 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2005 12:00AM |
| Updated: | Nov 03 2005 12:00AM |
| Credit: | Piotr Bania <[email protected]> reported this issue to the vendor. |
| Vulnerable: |
Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 6.5.2 Apple QuickTime Player 6.5.1 Apple QuickTime Player 6.5 Apple QuickTime Player 6.1 Apple QuickTime Player 5.0.2 Apple QuickTime Player 6 |
| Not Vulnerable: |
Apple QuickTime Player 7.0.3 |
Discussion
Apple QuickTime Null Pointer Dereference Denial of Service Vulnerability
QuickTime is prone to a denial of service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.
Successful exploitation of this vulnerability will cause the application to crash, effectively denying service to legitimate users.
This issue affects both Microsoft Windows, and Apple versions of QuickTime.
QuickTime is prone to a denial of service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.
Successful exploitation of this vulnerability will cause the application to crash, effectively denying service to legitimate users.
This issue affects both Microsoft Windows, and Apple versions of QuickTime.
Exploit / POC
Apple QuickTime Null Pointer Dereference Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple QuickTime Null Pointer Dereference Denial of Service Vulnerability
Solution:
Apple has released version 7.0.3 of QuickTime to address this, and other issues. Users are encouraged to utilize the built-in 'Software Update' feature to download and install fixes. Please see the referenced Apple document for further information.
Apple QuickTime Player 6
Apple QuickTime Player 5.0.2
Apple QuickTime Player 6.1
Apple QuickTime Player 6.5
Apple QuickTime Player 6.5.1
Apple QuickTime Player 6.5.2
Apple QuickTime Player 7.0
Apple QuickTime Player 7.0.1
Apple QuickTime Player 7.0.2
Solution:
Apple has released version 7.0.3 of QuickTime to address this, and other issues. Users are encouraged to utilize the built-in 'Software Update' feature to download and install fixes. Please see the referenced Apple document for further information.
Apple QuickTime Player 6
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 5.0.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
References
Apple QuickTime Null Pointer Dereference Denial of Service Vulnerability
References:
References:
- About the security content of QuickTime 7.0.3 (Apple)
- Apple QuickTime Homepage (Apple)
- Apple Security Updates (Apple)
- Advisory: Apple QuickTime Player Remote Denial Of Service (Piotr Bania
)