Apple QuickTime PICT Denial of Service Vulnerability
BID:31548
Info
Apple QuickTime PICT Denial of Service Vulnerability
| Bugtraq ID: | 31548 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-3629 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2008 12:00AM |
| Updated: | Oct 03 2008 02:18PM |
| Credit: | Sergio 'shadown' Alvarez of n.runs AG |
| Vulnerable: |
Apple TV 2.1 Apple TV 2.0 Apple TV 1.1 Apple TV 1.0 Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.1.6 Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple QuickTime Player 7.2 Apple QuickTime Player 7.1 |
| Not Vulnerable: |
Apple TV 2.2 Apple QuickTime Player 7.5.5 |
Discussion
Apple QuickTime PICT Denial of Service Vulnerability
Apple QuickTime is prone to a denial-of-service vulnerability.
This issue arises when the application handles specially crafted PICT image files. Successful exploits may allow attackers to crash the affected application, denying service to legitimate users.
NOTE: This issue was previously described in BID 31086 (Apple QuickTime Movie/PICT/QTVR Multiple Remote Vulnerabilities) but has been given its own record to better document the vulnerability.
The following are vulnerable:
QuickTime 7.5 and earlier
Apple TV 2.1 and earlier
Apple QuickTime is prone to a denial-of-service vulnerability.
This issue arises when the application handles specially crafted PICT image files. Successful exploits may allow attackers to crash the affected application, denying service to legitimate users.
NOTE: This issue was previously described in BID 31086 (Apple QuickTime Movie/PICT/QTVR Multiple Remote Vulnerabilities) but has been given its own record to better document the vulnerability.
The following are vulnerable:
QuickTime 7.5 and earlier
Apple TV 2.1 and earlier
Exploit / POC
Apple QuickTime PICT Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple QuickTime PICT Denial of Service Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Apple QuickTime Player 7.5
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Apple QuickTime Player 7.5
-
Apple iTunes8Setup.exe
http://www.apple.com/quicktime/download/ -
Apple QuickTime755_Leopard.dmg
http://www.apple.com/quicktime/download/ -
Apple QuickTime755_Tiger.dmg
http://www.apple.com/quicktime/download/ -
Apple QuickTimeInstaller.exe
http://www.apple.com/quicktime/download/