Apple QuickTime 'AAC-encoded' Media Memory Corruption Vulnerability
BID:29654
Info
Apple QuickTime 'AAC-encoded' Media Memory Corruption Vulnerability
| Bugtraq ID: | 29654 |
| Class: | Unknown |
| CVE: |
CVE-2008-1582 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 09 2008 12:00AM |
| Updated: | Jun 11 2008 08:22PM |
| Credit: | Dave Soldera of NGS Software, and Jens Alfke |
| Vulnerable: |
Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.1.6 Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 7.4 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple QuickTime Player 7.2 Apple QuickTime Player 7.1 |
| Not Vulnerable: |
Apple QuickTime Player 7.5 |
Discussion
Apple QuickTime 'AAC-encoded' Media Memory Corruption Vulnerability
Apple QuickTime is prone to a memory-corruption vulnerability that arises when the application handles specially crafted 'AAC-encoded' media files.
Successful exploits may allow remote attackers to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
NOTE: This issue was previously covered in BID 29619 (Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities) but has been given its own record to better document the vulnerability.
Versions prior to QuickTime 7.5 are affected.
Apple QuickTime is prone to a memory-corruption vulnerability that arises when the application handles specially crafted 'AAC-encoded' media files.
Successful exploits may allow remote attackers to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
NOTE: This issue was previously covered in BID 29619 (Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities) but has been given its own record to better document the vulnerability.
Versions prior to QuickTime 7.5 are affected.
Exploit / POC
Apple QuickTime 'AAC-encoded' Media Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple QuickTime 'AAC-encoded' Media Memory Corruption Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Apple QuickTime 'AAC-encoded' Media Memory Corruption Vulnerability
References:
References: