Apple QuickTime Malformed '.mpg' File Denial of Service Vulnerability
BID:35520
Info
Apple QuickTime Malformed '.mpg' File Denial of Service Vulnerability
| Bugtraq ID: | 35520 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2009 12:00AM |
| Updated: | Jun 29 2009 11:29PM |
| Credit: | Jared DeMott |
| Vulnerable: |
Apple QuickTime Player 7.6.2 Apple QuickTime Player 7.6.1 Apple QuickTime Player 7.5.5 Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.1.6 Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 6.5.2 Apple QuickTime Player 6.5.1 Apple QuickTime Player 6.5 Apple QuickTime Player 6.1 Apple QuickTime Player 7.6 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple QuickTime Player 7.2 Apple QuickTime Player 7.1 Apple QuickTime Player 6.4 Apple QuickTime Player 6 |
| Not Vulnerable: | |
Discussion
Apple QuickTime Malformed '.mpg' File Denial of Service Vulnerability
Apple QuickTime is prone to a denial-of-service vulnerability.
Successful exploits may allow an attacker to crash the affected application, denying service to legitimate users.
Apple QuickTime is prone to a denial-of-service vulnerability.
Successful exploits may allow an attacker to crash the affected application, denying service to legitimate users.
Exploit / POC
Apple QuickTime Malformed '.mpg' File Denial of Service Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim into viewing a malicious '.mpg' file.
An attacker can exploit this issue by enticing an unsuspecting victim into viewing a malicious '.mpg' file.
Solution / Fix
Apple QuickTime Malformed '.mpg' File Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple QuickTime Malformed '.mpg' File Denial of Service Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)
- Hacking QuickTime: Exception or Exploit (Jared DeMott)