Apple QuickTime/iTunes QuickTime.QTS Heap Overflow Vulnerability
BID:15732
Info
Apple QuickTime/iTunes QuickTime.QTS Heap Overflow Vulnerability
| Bugtraq ID: | 15732 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-4092 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2005 12:00AM |
| Updated: | Jan 11 2006 06:56PM |
| Credit: | Discovery is credited to Tom Ferris and Karl Lynn. |
| Vulnerable: |
Free-codecs.com QuickTime Alternative 1.67 Apple QuickTime Player 7.0.3 Apple iTunes 6.0.1 |
| Not Vulnerable: |
eSignal eSignal 6.0.2 Apple QuickTime Player 7.0.4 |
Discussion
Apple QuickTime/iTunes QuickTime.QTS Heap Overflow Vulnerability
A heap-based buffer overflow vulnerability has been reported in Apple QuickTime and iTunes. This issue affects both Mac OS X and Microsoft Windows releases of the software.
This issue may be triggered when the application processes a malformed movie (.MOV) file.
Successful exploitation will result in execution of arbitrary code in the context of the currently logged in user.
This issue affects Apple QuickTime 7.0.3 and iTunes 6.0.1. Earlier versions may also be affected.
A heap-based buffer overflow vulnerability has been reported in Apple QuickTime and iTunes. This issue affects both Mac OS X and Microsoft Windows releases of the software.
This issue may be triggered when the application processes a malformed movie (.MOV) file.
Successful exploitation will result in execution of arbitrary code in the context of the currently logged in user.
This issue affects Apple QuickTime 7.0.3 and iTunes 6.0.1. Earlier versions may also be affected.
Exploit / POC
Apple QuickTime/iTunes QuickTime.QTS Heap Overflow Vulnerability
The following example files were provided to demonstrate the vulnerability by crashing the application:
http://www.security-protocols.com/poc/sp-x21-1.mov <- crashes QuickTime
http://www.security-protocols.com/poc/sp-x21-2.mov <- crashes iTunes and QuickTime
Symantec has not tested the integrity of these files.
The following example files were provided to demonstrate the vulnerability by crashing the application:
http://www.security-protocols.com/poc/sp-x21-1.mov <- crashes QuickTime
http://www.security-protocols.com/poc/sp-x21-2.mov <- crashes iTunes and QuickTime
Symantec has not tested the integrity of these files.
Solution / Fix
Apple QuickTime/iTunes QuickTime.QTS Heap Overflow Vulnerability
Solution:
Apple has released advisory APPLE-SA-2006-01-10 and fixes to address this issue.
Apple iTunes 6.0.1
Apple QuickTime Player 7.0.3
Solution:
Apple has released advisory APPLE-SA-2006-01-10 and fixes to address this issue.
Apple iTunes 6.0.1
-
Apple iTunes 6.0.2
http://www.apple.com/itunes/download/
Apple QuickTime Player 7.0.3
-
Apple QuickTime 7.0.4
http://www.apple.com/quicktime/
References
Apple QuickTime/iTunes QuickTime.QTS Heap Overflow Vulnerability
References:
References:
- Apple QuickTime 7.0.3 & iTunes 6.0.1 Heap Overflow (Security-Protocols)
- QuickTime Alternative Home Page (Free-codecs.com)
- Upcoming Release: Apple Quicktime/iTunes Heap Overflow (Security-Protocols)
- [EEYEB-20051117A] Apple QuickTime STSD Atom Heap Overflow ("Advisories"
) - [EEYEB-20051117B] Apple iTunes (QuickTime.qts) Heap Overflow ("Advisories"
)