Apple QuickTime Indo Video Codec Buffer Overflow Vulnerability
BID:29652
Info
Apple QuickTime Indo Video Codec Buffer Overflow Vulnerability
| Bugtraq ID: | 29652 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1584 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2008 12:00AM |
| Updated: | Jun 11 2008 07:32PM |
| Credit: | anonymous researcher from TippingPoint's Zero Day Initiative |
| Vulnerable: |
Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.1.6 Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.4 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple QuickTime Player 7.2 Apple QuickTime Player 7.1 |
| Not Vulnerable: |
Apple QuickTime Player 7.5 |
Discussion
Apple QuickTime Indo Video Codec Buffer Overflow Vulnerability
Apple QuickTime is prone to a buffer-overflow vulnerability that may allow remote attackers to execute arbitrary code.
Successful exploits may allow attackers to gain remote unauthorized access in the context of a vulnerable user; failed exploits will cause denial-of-service conditions.
NOTE: This issue was previously covered in BID 29619 (Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities) but has been given its own record to better document the vulnerability.
Versions prior to QuickTime 7.5 are affected.
Apple QuickTime is prone to a buffer-overflow vulnerability that may allow remote attackers to execute arbitrary code.
Successful exploits may allow attackers to gain remote unauthorized access in the context of a vulnerable user; failed exploits will cause denial-of-service conditions.
NOTE: This issue was previously covered in BID 29619 (Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities) but has been given its own record to better document the vulnerability.
Versions prior to QuickTime 7.5 are affected.
Exploit / POC
Apple QuickTime Indo Video Codec Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple QuickTime Indo Video Codec Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Apple QuickTime Indo Video Codec Buffer Overflow Vulnerability
References:
References: