Apple QuickTime Plug-In Arbitrary Script Execution Weakness
BID:20138
CVE-2006-4965 |Info
Apple QuickTime Plug-In Arbitrary Script Execution Weakness
| Bugtraq ID: | 20138 |
| Class: | Design Error |
| CVE: |
CVE-2006-4965 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2006 12:00AM |
| Updated: | Mar 19 2015 08:50AM |
| Credit: | pdp of gnucitizen.org is credited with the discovery of this vulnerability. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE openSUSE 10.3 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 Slackware Linux 10.2 Slackware Linux 12.0 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc Red Hat Fedora Core6 Netscape Navigator 8.1.3 Mozilla Firefox 2.0 .6 Mozilla Firefox 2.0 .5 Mozilla Firefox 2.0 .4 Mozilla Firefox 2.0 .3 Mozilla Firefox 2.0 .1 Mozilla Firefox 2.0.0.2 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Apple QuickTime Plug-In 7.1.3 |
| Not Vulnerable: |
Netscape Navigator 9.0 Mozilla Firefox 2.0 .7 |
Discussion
Apple QuickTime Plug-In Arbitrary Script Execution Weakness
Apple QuickTime plug-in is prone to an arbitrary-script-execution weakness when executing QuickTime Media Link files (.qtl).
An attacker can exploit this issue to execute arbitrary script code in the context of the affected application and load local content in a user's browser. Although this weakness doesn't pose any direct security threat by itself, an attacker may use it to aid in further attacks.
QuickTime 7.1.3 is vulnerable; other versions may also be affected.
Apple QuickTime plug-in is prone to an arbitrary-script-execution weakness when executing QuickTime Media Link files (.qtl).
An attacker can exploit this issue to execute arbitrary script code in the context of the affected application and load local content in a user's browser. Although this weakness doesn't pose any direct security threat by itself, an attacker may use it to aid in further attacks.
QuickTime 7.1.3 is vulnerable; other versions may also be affected.
Exploit / POC
Apple QuickTime Plug-In Arbitrary Script Execution Weakness
The following proof-of-concept QuickTime Media Link files are available; they use the '.mp3' file extension.
A sample exploit written in the Ruby programming language has also been provided.
The following proof-of-concept QuickTime Media Link files are available; they use the '.mp3' file extension.
A sample exploit written in the Ruby programming language has also been provided.
Solution / Fix
Apple QuickTime Plug-In Arbitrary Script Execution Weakness
Solution:
Please see the referenced advisories for more information.
Slackware Linux 12.0
Slackware Linux -current
Slackware Linux 11.0
Slackware Linux 10.2
Solution:
Please see the referenced advisories for more information.
Slackware Linux 12.0
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1_slack12.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/ seamonkey-1.1.5-i486-1_slack12.tgz
Slackware Linux -current
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/ seamonkey-1.1.5-i486-1.tgz
Slackware Linux 11.0
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz -
Slackware seamonkey-1.1.5-i486-1_slack11.0.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/ seamonkey-1.1.5-i486-1_slack11.0.tgz
Slackware Linux 10.2
-
Slackware mozilla-firefox-2.0.0.8-i686-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ mozilla-firefox-2.0.0.8-i686-1.tgz
References
Apple QuickTime Plug-In Arbitrary Script Execution Weakness
References:
References:
- 0DAY: QuickTime pwns Firefox (pdp (architect))
- Apple QuickTime Homepage (Apple)
- Backdooring MP3 Files (pdp)
- MOAB-03-01-2007: Apple Quicktime HREFTrack Cross-Zone Scripting vulnerability (lmh)
- Netscape Navigator Release Notes (Netscape)
- New Netscape Navigator 9 ships security fixes and is multi-platform (Securiteam)
- 0DAY: QuickTime pwns Firefox ("pdp (architect)"
) - APPLE-SA-2007-03-05 QuickTime 7.1.5 (Apple)
- Mozilla Foundation Security Advisory 2007-28 Code execution via QuickTime Media- (Mozilla)