Apple QuickTime Compressed PICT Data Remote Buffer Overflow Vulnerability
BID:15309
Info
Apple QuickTime Compressed PICT Data Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 15309 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2756 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2005 12:00AM |
| Updated: | Nov 03 2005 12:00AM |
| Credit: | Piotr Bania <[email protected]> reported this issue to the vendor. |
| Vulnerable: |
Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 6.5.2 Apple QuickTime Player 6.5.1 Apple QuickTime Player 6.5 Apple QuickTime Player 6.1 Apple QuickTime Player 5.0.2 Apple QuickTime Player 6 |
| Not Vulnerable: |
Apple QuickTime Player 7.0.3 |
Discussion
Apple QuickTime Compressed PICT Data Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability affects Apple QuickTime. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.
This issue affects both Microsoft Windows, and Apple versions of QuickTime.
A remote buffer overflow vulnerability affects Apple QuickTime. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.
An attacker may leverage this issue to cause the affected QuickTime client to crash, denying service to legitimate users. It has been speculated that this issue may also facilitate code execution; any code execution would occur with the privileges of the user that activated the affected software.
This issue affects both Microsoft Windows, and Apple versions of QuickTime.
Exploit / POC
Apple QuickTime Compressed PICT Data Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple QuickTime Compressed PICT Data Remote Buffer Overflow Vulnerability
Solution:
Apple has released version 7.0.3 of QuickTime to address this, and other issues. Users are encouraged to utilize the built-in 'Software Update' feature to download and install fixes. Please see the referenced Apple document for further information.
Apple QuickTime Player 6
Apple QuickTime Player 5.0.2
Apple QuickTime Player 6.1
Apple QuickTime Player 6.5
Apple QuickTime Player 6.5.1
Apple QuickTime Player 6.5.2
Apple QuickTime Player 7.0
Apple QuickTime Player 7.0.1
Apple QuickTime Player 7.0.2
Solution:
Apple has released version 7.0.3 of QuickTime to address this, and other issues. Users are encouraged to utilize the built-in 'Software Update' feature to download and install fixes. Please see the referenced Apple document for further information.
Apple QuickTime Player 6
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 5.0.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 6.5.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0.1
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
Apple QuickTime Player 7.0.2
-
Apple QuickTime 7.0.3
http://www.apple.com/support/downloads/quicktime703.html
References
Apple QuickTime Compressed PICT Data Remote Buffer Overflow Vulnerability
References:
References:
- About the security content of QuickTime 7.0.3 (Apple)
- Apple QuickTime Homepage (Apple)
- Apple Security Updates (Apple)
- Advisory: Apple QuickTime PICT Remote Memory Overwrite (Piotr Bania
)