Apple QuickTime Information Disclosure and Multiple Code Execution Vulnerabilities
BID:24873
Info
Apple QuickTime Information Disclosure and Multiple Code Execution Vulnerabilities
| Bugtraq ID: | 24873 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-2392 CVE-2007-2394 CVE-2007-2397 CVE-2007-2393 CVE-2007-2396 CVE-2007-2402 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2007 12:00AM |
| Updated: | Sep 05 2007 06:21PM |
| Credit: | The vendor disclosed some of these issues. Some issues are credited to: Jonathan 'Wolf' Rentzsch of Red Shed Software (CVE-2007-2392) David Vaartjes of ITsec Security Services (CVE-2007-2394) Adam Gowdiak (CVE-2007-2397, CVE-2007-2393, CVE-2007-2396) |
| Vulnerable: |
Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 6.5.2 Apple QuickTime Player 6.5.1 Apple QuickTime Player 6.5 Apple QuickTime Player 6.1 Apple QuickTime Player 5.0.2 Apple QuickTime Player 7.1 Apple QuickTime Player 6 |
| Not Vulnerable: |
Apple Quicktime 7.2 |
Discussion
Apple QuickTime Information Disclosure and Multiple Code Execution Vulnerabilities
Apple QuickTime is prone to an information-disclosure and multiple remote code-execution vulnerabilities.
Remote attackers may exploit these issues by enticing victims into opening maliciously crafted files or visiting maliciously crafted websites.
Successful exploits may allow attackers to execute arbitrary code in the context of a user running the vulnerable application or to obtain sensitive information. Failed exploit attempts of remote code-execution issues may result in denial-of-service conditions. Successful exploits of the information-disclosure issue may lead to further attacks.
Apple QuickTime is prone to an information-disclosure and multiple remote code-execution vulnerabilities.
Remote attackers may exploit these issues by enticing victims into opening maliciously crafted files or visiting maliciously crafted websites.
Successful exploits may allow attackers to execute arbitrary code in the context of a user running the vulnerable application or to obtain sensitive information. Failed exploit attempts of remote code-execution issues may result in denial-of-service conditions. Successful exploits of the information-disclosure issue may lead to further attacks.
Exploit / POC
Apple QuickTime Information Disclosure and Multiple Code Execution Vulnerabilities
An attacker may exploit these issues by enticing a victim into visiting a malicious webpage or opening a maliciously crafted file.
A proof-of-concept exploit is available.
An attacker may exploit these issues by enticing a victim into visiting a malicious webpage or opening a maliciously crafted file.
A proof-of-concept exploit is available.
Solution / Fix
Apple QuickTime Information Disclosure and Multiple Code Execution Vulnerabilities
Solution:
The vendor released an advisory and fixes to address these issues. Please see the references for more information.
Dan Harkless <[email protected]> states that fixes are not available for Microsoft Windows 2000 computers. Symantec has not confirmed this.
Users of affected packages running on Windows 2000 computers should contact Apple for information on obtaining and applying fixes. Please see the references for details.
Solution:
The vendor released an advisory and fixes to address these issues. Please see the references for more information.
Dan Harkless <[email protected]> states that fixes are not available for Microsoft Windows 2000 computers. Symantec has not confirmed this.
Users of affected packages running on Windows 2000 computers should contact Apple for information on obtaining and applying fixes. Please see the references for details.
References
Apple QuickTime Information Disclosure and Multiple Code Execution Vulnerabilities
References:
References:
- Cisco TelePresence Video Communication Server (VCS) Homepage (Cisco)
- Re: iDefense Security Advisory 07.11.07: Apple QuickTime SMIL File Processing In (Dan Harkless
) - About the security content of QuickTime 7.2 (Apple)
- Apple QuickTime SMIL File Processing Integer Overflow Vulnerability (iDefense)
- Technical Cyber Security Alert TA07-193A (US-CERT)
- Vulnerability Note VU#582681 Apple QuickTime fails to properly handle malformed (US-CERT)