Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vulnerability
BID:32540
Info
Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vulnerability
| Bugtraq ID: | 32540 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-5406 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2008 12:00AM |
| Updated: | Apr 13 2015 09:12PM |
| Credit: | laurent gaffié |
| Vulnerable: |
Apple Quicktime X 0 Apple QuickTime Player 7.6.5 Apple QuickTime Player 7.6.4 Apple QuickTime Player 7.6.2 Apple QuickTime Player 7.6.1 Apple QuickTime Player 7.5.5 Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.6 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple Quicktime 7.3.4 Apple iTunes 9.0.1 .8 Apple iTunes 9.0.1 Apple iTunes 9.0 Apple iTunes 8.2 Apple iTunes 8.1 Apple iTunes 8.0.2.20 Apple iTunes 8.0 |
| Not Vulnerable: | |
Discussion
Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vulnerability
Apple iTunes and QuickTime are prone to a buffer-overflow vulnerability because the applications fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects the following:
iTunes 8.0.2.20 through 9.0.1.8
QuickTime 7.3.4 through QuickTime X
Additional versions or applications that rely on the QuickTime library may also be affected.
Apple iTunes and QuickTime are prone to a buffer-overflow vulnerability because the applications fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects the following:
iTunes 8.0.2.20 through 9.0.1.8
QuickTime 7.3.4 through QuickTime X
Additional versions or applications that rely on the QuickTime library may also be affected.
Exploit / POC
Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vulnerability
The following proofs of concept are available.
The following proofs of concept are available.
Solution / Fix
Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple iTunes/QuickTime Malformed '.mov' File Buffer Overflow Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)
- Buffer overflow in Quicktime (SANS Internet Storm Center)
- iTunes Homepage (Apple)