Apple QuickTime MPEG-2 Playback Component Remote Memory Corruption Vulnerability
BID:33393
Info
Apple QuickTime MPEG-2 Playback Component Remote Memory Corruption Vulnerability
| Bugtraq ID: | 33393 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0008 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2009 12:00AM |
| Updated: | Jan 21 2009 10:02PM |
| Credit: | Richard Lemon of Code Lemon |
| Vulnerable: |
Apple QuickTime MPEG-2 Playback Component 7.60 |
| Not Vulnerable: |
Apple QuickTime MPEG-2 Playback Component 7.60.92 0 |
Discussion
Apple QuickTime MPEG-2 Playback Component Remote Memory Corruption Vulnerability
The Apple QuickTime MPEG-2 Playback Component is prone to a memory-corruption issue because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted movie file.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the user running the application. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime MPEG-2 Playback Component running on Microsoft Windows Vista and Windows XP SP2 and SP3.
The Apple QuickTime MPEG-2 Playback Component is prone to a memory-corruption issue because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue by enticing an unsuspecting user to open a specially crafted movie file.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the user running the application. Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Apple QuickTime MPEG-2 Playback Component running on Microsoft Windows Vista and Windows XP SP2 and SP3.
Exploit / POC
Apple QuickTime MPEG-2 Playback Component Remote Memory Corruption Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple QuickTime MPEG-2 Playback Component Remote Memory Corruption Vulnerability
Solution:
The vendor has released an update and an advisory. Please see the references for more information.
Solution:
The vendor has released an update and an advisory. Please see the references for more information.
References
Apple QuickTime MPEG-2 Playback Component Remote Memory Corruption Vulnerability
References:
References: