Apple QuickTime TGA Image Processing Remote Integer Overflow Vulnerability
BID:16873
Info
Apple QuickTime TGA Image Processing Remote Integer Overflow Vulnerability
| Bugtraq ID: | 16873 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3708 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2006 12:00AM |
| Updated: | May 01 2008 07:16PM |
| Credit: | Discovery is credited to Dejun Meng of Fortinet. |
| Vulnerable: |
Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 |
| Not Vulnerable: |
Apple QuickTime Player 7.0.4 |
Discussion
Apple QuickTime TGA Image Processing Remote Integer Overflow Vulnerability
QuickTime is prone to a remote integer-overflow vulnerability.
This issue presents itself when the application processes a specially crafted TGA file.
A successful attack can result in a remote compromise.
Versions prior to QuickTime 7.0.4 are vulnerable.
NOTE: This issue was previously discussed in BID 16202 (Apple QuickTime Multiple Code Execution Vulnerabilities), but has been assigned its own record to better document the vulnerability.
QuickTime is prone to a remote integer-overflow vulnerability.
This issue presents itself when the application processes a specially crafted TGA file.
A successful attack can result in a remote compromise.
Versions prior to QuickTime 7.0.4 are vulnerable.
NOTE: This issue was previously discussed in BID 16202 (Apple QuickTime Multiple Code Execution Vulnerabilities), but has been assigned its own record to better document the vulnerability.
Exploit / POC
Apple QuickTime TGA Image Processing Remote Integer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple QuickTime TGA Image Processing Remote Integer Overflow Vulnerability
Solution:
Apple has released advisory APPLE-SA-2006-01-10 including QuickTime 7.0.4 to address this issue. Please see the referenced advisory for more information.
Apple QuickTime Player 7.0.3
Solution:
Apple has released advisory APPLE-SA-2006-01-10 including QuickTime 7.0.4 to address this issue. Please see the referenced advisory for more information.
Apple QuickTime Player 7.0.3
-
Apple QuickTime 7.0.4
http://www.apple.com/quicktime/
References
Apple QuickTime TGA Image Processing Remote Integer Overflow Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)