Apple QuickTime Pictureviewer Multiple DLL Loading Arbitrary Code Execution Vulnerability
BID:42774
Info
Apple QuickTime Pictureviewer Multiple DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 42774 |
| Class: | Design Error |
| CVE: |
CVE-2010-1819 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2010 12:00AM |
| Updated: | Sep 16 2010 03:01PM |
| Credit: | Kalyan and Haifei Li of Fortinet's FortiGuard Labs |
| Vulnerable: |
Apple QuickTime Player 7.6.7 Apple QuickTime Player 7.6.6 (1671) Apple QuickTime Player 7.6.6 Apple QuickTime Player 7.6.5 Apple QuickTime Player 7.6.4 Apple QuickTime Player 7.6.2 Apple QuickTime Player 7.6.1 Apple QuickTime Player 7.5.5 Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.1.6 Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 7.64.17.73 Apple QuickTime Player 7.6 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple QuickTime Player 7.2 Apple QuickTime Player 7.1 Apple Quicktime 7.3.4 Apple Quicktime 7.2 |
| Not Vulnerable: |
Apple QuickTime Player 7.6.8 |
Discussion
Apple QuickTime Pictureviewer Multiple DLL Loading Arbitrary Code Execution Vulnerability
Apple Quicktime Pictureviewer is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Apple Quicktime Pictureviewer is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Exploit / POC
Apple QuickTime Pictureviewer Multiple DLL Loading Arbitrary Code Execution Vulnerability
Attackers must trick a victim into opening a file on a remote WebDAV or SMB share to exploit this issue.
Attackers must trick a victim into opening a file on a remote WebDAV or SMB share to exploit this issue.
Solution / Fix
Apple QuickTime Pictureviewer Multiple DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Apple QuickTime Player 7.6.7
Solution:
Vendor updates are available. Please see the references for more information.
Apple QuickTime Player 7.6.7
-
Apple APPLE-SA-2010-09-15-1 QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP2 or later
http://www.apple.com/quicktime/download/
References
Apple QuickTime Pictureviewer Multiple DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)
- Application DLL Load Hijacking (HD Moore)
- CAD 2D-3D Pipe designing software Microstation, Nero, Quicktime Pictureviwer vul (kalyan)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Microsoft Security Advisory (2269637) (Microsoft)