Apple QuickTime Multiple Remote Vulnerabilities
BID:28583
Info
Apple QuickTime Multiple Remote Vulnerabilities
| Bugtraq ID: | 28583 |
| Class: | Unknown |
| CVE: |
CVE-2008-1013 CVE-2008-1014 CVE-2008-1015 CVE-2008-1016 CVE-2008-1017 CVE-2008-1018 CVE-2008-1019 CVE-2008-1020 CVE-2008-1021 CVE-2008-1022 CVE-2008-1023 APPLE-SA-2008-07-10 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2008 12:00AM |
| Updated: | Jul 10 2008 07:19PM |
| Credit: | Adam Gowdiak, Vinoo Thomas, Rahul Mohandas, Chris Ries, Sanbin Li, bugfree, Ruben Santamarta, Wei Wang, and anonymous researchers. |
| Vulnerable: |
Apple TV 2.0 Apple TV 1.1 Apple TV 1.0 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.1.6 Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.4 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple QuickTime Player 7.2 Apple QuickTime Player 7.1 |
| Not Vulnerable: |
Apple TV 2.1 Apple QuickTime Player 7.4.5 |
Discussion
Apple QuickTime Multiple Remote Vulnerabilities
Apple QuickTime is prone to multiple remote vulnerabilities that may allow remote attackers to obtain sensitive information, execute arbitrary code, and carry out denial-of-service attacks.
These issues arise when the application handles specially crafted Java applets, image files, and movie files. Successful exploits may allow attackers to obtain sensitive information, gain remote unauthorized access in the context of a vulnerable user, and trigger a denial-of-service condition.
Versions prior to QuickTime 7.4.5 are affected by these vulnerabilities.
Apple QuickTime is prone to multiple remote vulnerabilities that may allow remote attackers to obtain sensitive information, execute arbitrary code, and carry out denial-of-service attacks.
These issues arise when the application handles specially crafted Java applets, image files, and movie files. Successful exploits may allow attackers to obtain sensitive information, gain remote unauthorized access in the context of a vulnerable user, and trigger a denial-of-service condition.
Versions prior to QuickTime 7.4.5 are affected by these vulnerabilities.
Exploit / POC
Apple QuickTime Multiple Remote Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple QuickTime Multiple Remote Vulnerabilities
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Apple QuickTime Multiple Remote Vulnerabilities
References:
References:
- Apple QuickTime Homepage (Apple)
- ZDI-08-014: Apple Quicktime Multiple Opcode Memory Corruption Vulnerabilities ([email protected])
- ZDI-08-015: Apple QuickTime Clipping Region Heap Overflow Vulnerability ([email protected])
- ZDI-08-016: Apple QuickTime MP4A Atom Parsing Heap Corruption Vulnerability ([email protected])
- ZDI-08-017: Apple QuickTime Kodak Encoding Heap Overflow Vulnerability ([email protected])
- ZDI-08-018: Apple QuickTime Run Length Encoding Heap Overflow Vulnerability ([email protected])
- ZDI-08-014 Apple Quicktime Multiple Opcode Memory Corruption Vulnerabilities (Zero Day Initiative)
- ZDI-08-015 Apple QuickTime Clipping Region Heap Overflow Vulnerability (Zero Day Initiative)
- ZDI-08-016 Apple QuickTime MP4A Atom Parsing Heap Corruption Vulnerability (Zero Day Initiative)
- ZDI-08-017 Apple QuickTime Kodak Encoding Heap Overflow Vulnerability (Zero Day Initiative)
- ZDI-08-018 Apple QuickTime Run Length Encoding Heap Overflow Vulnerability (Zero Day Initiative)
- ZDI-08-019 Apple QuickTime Malformed VR obji Atom Parsing Memory Corruption Vuln (Zero Day Initiative)
- ZDI-08-019: Apple QuickTime Malformed VR obji Atom Parsing Memory Corruption Vul ([email protected])