Apple QuickTime Unspecified Remote Code Execution Vulnerability
BID:28959
Info
Apple QuickTime Unspecified Remote Code Execution Vulnerability
| Bugtraq ID: | 28959 |
| Class: | Unknown |
| CVE: |
CVE-2008-2010 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2008 12:00AM |
| Updated: | Apr 30 2008 05:26PM |
| Credit: | pdp from GNUCITIZEN |
| Vulnerable: |
Apple QuickTime Player 7.4 |
| Not Vulnerable: | |
Discussion
Apple QuickTime Unspecified Remote Code Execution Vulnerability
Apple QuickTime is prone to an unspecified remote code-execution vulnerability.
Very few technical details are currently available. We will update this BID as more information emerges.
Successful exploits can allow remote attackers to execute arbitrary code in the context of the user running the application. This may facilitate a compromise of affected computers.
This issue affects QuickTime 7.4 for Microsoft Windows XP and Vista; other versions may also be affected.
Apple QuickTime is prone to an unspecified remote code-execution vulnerability.
Very few technical details are currently available. We will update this BID as more information emerges.
Successful exploits can allow remote attackers to execute arbitrary code in the context of the user running the application. This may facilitate a compromise of affected computers.
This issue affects QuickTime 7.4 for Microsoft Windows XP and Vista; other versions may also be affected.
Exploit / POC
Apple QuickTime Unspecified Remote Code Execution Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious file.
The following video is available to illustrate a successful exploit:
http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/
An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious file.
The following video is available to illustrate a successful exploit:
http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/
Solution / Fix
Apple QuickTime Unspecified Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple QuickTime Unspecified Remote Code Execution Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)
- QuickTime 0day for Vista and XP (GNUCITIZEN)