Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow Vulnerability
BID:41962
Info
Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 41962 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-1799 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2010 12:00AM |
| Updated: | Aug 17 2010 07:34AM |
| Credit: | Krystian Kloskowski (h07) |
| Vulnerable: |
Apple QuickTime Player 7.6.6 (1671) Apple QuickTime Player 7.6.6 Apple QuickTime Player 7.6.5 Apple QuickTime Player 7.6.4 Apple QuickTime Player 7.6.2 Apple QuickTime Player 7.6.1 Apple QuickTime Player 7.5.5 Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.1.6 Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 7.6 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple QuickTime Player 7.2 Apple QuickTime Player 7.1 |
| Not Vulnerable: |
Apple QuickTime Player 7.6.7 |
Discussion
Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow Vulnerability
Apple QuickTime is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
QuickTime 7.6.6 (1671) for Windows is vulnerable; other versions may also be affected.
Apple QuickTime is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data
An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
QuickTime 7.6.6 (1671) for Windows is vulnerable; other versions may also be affected.
Exploit / POC
Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the referenced advisory for more information.
Apple QuickTime Player 7.6.6
Apple QuickTime Player 7.6.6 (1671)
Solution:
Vendor updates are available. Please see the referenced advisory for more information.
Apple QuickTime Player 7.6.6
-
Apple APPLE-SA-2010-08-12-1 QuickTimeInstaller.exe
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.6 (1671)
-
Apple APPLE-SA-2010-08-12-1 QuickTimeInstaller.exe
http://www.apple.com/quicktime/download/
References
Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)