Apple Quicktime UDTA ATOM Integer Overflow Vulnerability
BID:22844
Info
Apple Quicktime UDTA ATOM Integer Overflow Vulnerability
| Bugtraq ID: | 22844 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-0714 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2007 12:00AM |
| Updated: | Mar 07 2007 08:05PM |
| Credit: | Sowhat of Nevis Labs discovered this vulnerability. |
| Vulnerable: |
Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 6.5.2 Apple QuickTime Player 6.5.1 Apple QuickTime Player 6.5 Apple QuickTime Player 6.1 Apple QuickTime Player 5.0.2 Apple QuickTime Player 7.1 Apple QuickTime Player 6 |
| Not Vulnerable: |
Apple QuickTime Player 7.1.5 |
Discussion
Apple Quicktime UDTA ATOM Integer Overflow Vulnerability
Apple QuickTime is prone to an integer-overflow vulnerability when processing specially crafted MOV files.
An attacker can exploit this issue to execute arbitrary code in the context of a user running the application. Failed attempts can cause denial-of-service conditions.
Versions prior to 7.1.5 are vulnerable.
This issue was previously discussed in BID 22827 (Apple QuickTime Multiple Unspecified Code Execution Vulnerabilities), but has been assigned its own record because of new information.
Apple QuickTime is prone to an integer-overflow vulnerability when processing specially crafted MOV files.
An attacker can exploit this issue to execute arbitrary code in the context of a user running the application. Failed attempts can cause denial-of-service conditions.
Versions prior to 7.1.5 are vulnerable.
This issue was previously discussed in BID 22827 (Apple QuickTime Multiple Unspecified Code Execution Vulnerabilities), but has been assigned its own record because of new information.
Exploit / POC
Apple Quicktime UDTA ATOM Integer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious MOV file.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious MOV file.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Apple Quicktime UDTA ATOM Integer Overflow Vulnerability
Solution:
Apple has released advisory APPLE-SA-2007-03-05 and QuickTime 7.1.5 to address this issue. Please see the references for more information.
Solution:
Apple has released advisory APPLE-SA-2007-03-05 and QuickTime 7.1.5 to address this issue. Please see the references for more information.
References
Apple Quicktime UDTA ATOM Integer Overflow Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)
- Quicktime Downloads Page (Apple)
- Apple QuickTime udta ATOM Integer Overflow (Sowhat)
- ZDI-07-010 Apple Quicktime UDTA Parsing Heap Overflow Vulnerability (Zero Day Initiative (ZDI))
- APPLE-SA-2007-03-05 QuickTime 7.1.5 (Apple)
- VU#861817 Apple QuickTime UDTA atom integer overflow (US-CERT)