Apple QuickTime TGA Image Processing Remote Buffer Overflow Vulnerability
BID:16872
Info
Apple QuickTime TGA Image Processing Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 16872 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3707 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2006 12:00AM |
| Updated: | May 01 2008 09:36PM |
| Credit: | Discovery is credited to Dejun Meng of Fortinet. |
| Vulnerable: |
Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 |
| Not Vulnerable: |
Apple QuickTime Player 7.0.4 |
Discussion
Apple QuickTime TGA Image Processing Remote Buffer Overflow Vulnerability
QuickTime is prone to a remote buffer-overflow vulnerability.
This issue presents itself when the application processes a specially crafted TGA image file.
A successful attack can result in a remote compromise.
Versions prior to QuickTime 7.0.4 are vulnerable.
NOTE: This issue was previously discussed in BID 16202 (Apple QuickTime Multiple Code Execution Vulnerabilities), but has been assigned its own record to better document the vulnerability.
QuickTime is prone to a remote buffer-overflow vulnerability.
This issue presents itself when the application processes a specially crafted TGA image file.
A successful attack can result in a remote compromise.
Versions prior to QuickTime 7.0.4 are vulnerable.
NOTE: This issue was previously discussed in BID 16202 (Apple QuickTime Multiple Code Execution Vulnerabilities), but has been assigned its own record to better document the vulnerability.
Exploit / POC
Apple QuickTime TGA Image Processing Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple QuickTime TGA Image Processing Remote Buffer Overflow Vulnerability
Solution:
Apple has released advisory APPLE-SA-2006-01-10 including QuickTime 7.0.4 to address this issue. Please see the referenced advisory for more information.
Apple QuickTime Player 7.0.3
Solution:
Apple has released advisory APPLE-SA-2006-01-10 including QuickTime 7.0.4 to address this issue. Please see the referenced advisory for more information.
Apple QuickTime Player 7.0.3
-
Apple QuickTime 7.0.4
http://www.apple.com/quicktime/
References
Apple QuickTime TGA Image Processing Remote Buffer Overflow Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)