RETIRED: Apple QuickTime Prior To 7.7 Multiple Arbitrary Code Execution Vulnerabilities
BID:48993
Info
RETIRED: Apple QuickTime Prior To 7.7 Multiple Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 48993 |
| Class: | Unknown |
| CVE: |
CVE-2011-0245 CVE-2011-0246 CVE-2011-0247 CVE-2011-0248 CVE-2011-0249 CVE-2011-0250 CVE-2011-0251 CVE-2011-0252 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2011 12:00AM |
| Updated: | Aug 03 2011 12:00AM |
| Credit: | Subreption LLC working with TippingPoint's Zero Day Initiative, an anonymous contributor working with Beyond Security's SecuriTeam Secure Disclosure program, Roi Mallo and Sherab Giovannini working with TippingPoint's Zero Day Initiative, Chkr_d591 working |
| Vulnerable: |
Apple QuickTime Player 7.6.8 Apple QuickTime Player 7.6.7 Apple QuickTime Player 7.6.6 (1671) Apple QuickTime Player 7.6.6 Apple QuickTime Player 7.6.5 Apple QuickTime Player 7.6.4 Apple QuickTime Player 7.6.2 Apple QuickTime Player 7.6.1 Apple QuickTime Player 7.5.5 Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.64.17.73 Apple QuickTime Player 7.6.9 Apple QuickTime Player 7.6 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 |
| Not Vulnerable: |
Apple QuickTime Player 7.7 |
Discussion
RETIRED: Apple QuickTime Prior To 7.7 Multiple Arbitrary Code Execution Vulnerabilities
Apple QuickTime is prone to multiple vulnerabilities that may allow remote attackers to execute arbitrary code.
These issues arise when the application handles specially crafted pict, GIF, H.264, QTL, and QuickTime files. Successful exploits may allow attackers to execute arbitrary code in the context of the currently logged-in user; failed exploit attempts will cause denial-of-service conditions.
Versions prior to QuickTime 7.7 are vulnerable on Windows 7, Vista, XP, and Mac OS X platforms.
This BID is being retired. The following individual records exist to better document the issues:
49028 Apple QuickTime CVE-2011-0245 Pict File Buffer Overflow Vulnerability
49029 Apple QuickTime CVE-2011-0246 GIF Image Heap Buffer Overflow Vulnerability
49030 Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
49031 Apple QuickTime ActiveX QTL File CVE-2011-0248 Stack Buffer Overflow Vulnerability
49034 Apple QuickTime CVE-2011-0249 STSC Atoms Heap Buffer Overflow Vulnerability
49035 Apple QuickTime CVE-2011-0250 STSS Atoms Heap Buffer Overflow Vulnerability
49036 Apple QuickTime CVE-2011-0251 STSZ Atoms Heap Buffer Overflow Vulnerability
49038 Apple QuickTime CVE-2011-0252 STTS Atoms Heap Buffer Overflow Vulnerability
Apple QuickTime is prone to multiple vulnerabilities that may allow remote attackers to execute arbitrary code.
These issues arise when the application handles specially crafted pict, GIF, H.264, QTL, and QuickTime files. Successful exploits may allow attackers to execute arbitrary code in the context of the currently logged-in user; failed exploit attempts will cause denial-of-service conditions.
Versions prior to QuickTime 7.7 are vulnerable on Windows 7, Vista, XP, and Mac OS X platforms.
This BID is being retired. The following individual records exist to better document the issues:
49028 Apple QuickTime CVE-2011-0245 Pict File Buffer Overflow Vulnerability
49029 Apple QuickTime CVE-2011-0246 GIF Image Heap Buffer Overflow Vulnerability
49030 Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
49031 Apple QuickTime ActiveX QTL File CVE-2011-0248 Stack Buffer Overflow Vulnerability
49034 Apple QuickTime CVE-2011-0249 STSC Atoms Heap Buffer Overflow Vulnerability
49035 Apple QuickTime CVE-2011-0250 STSS Atoms Heap Buffer Overflow Vulnerability
49036 Apple QuickTime CVE-2011-0251 STSZ Atoms Heap Buffer Overflow Vulnerability
49038 Apple QuickTime CVE-2011-0252 STTS Atoms Heap Buffer Overflow Vulnerability
Exploit / POC
RETIRED: Apple QuickTime Prior To 7.7 Multiple Arbitrary Code Execution Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: Apple QuickTime Prior To 7.7 Multiple Arbitrary Code Execution Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Apple QuickTime Player 7.6
Apple QuickTime Player 7.6.9
Apple QuickTime Player 7.6.1
Apple QuickTime Player 7.6.2
Apple QuickTime Player 7.6.4
Apple QuickTime Player 7.6.5
Apple QuickTime Player 7.6.6
Apple QuickTime Player 7.6.6 (1671)
Apple QuickTime Player 7.6.7
Apple QuickTime Player 7.6.8
Solution:
Vendor updates are available. Please see the references for more information.
Apple QuickTime Player 7.6
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.9
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.1
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.2
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.4
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.5
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.6
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.6 (1671)
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.7
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.8
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
References
RETIRED: Apple QuickTime Prior To 7.7 Multiple Arbitrary Code Execution Vulnerabilities
References:
References:
- Apple QuickTime Homepage (Apple)