Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
BID:49030
Info
Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 49030 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-0247 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2011 12:00AM |
| Updated: | Oct 24 2011 04:52PM |
| Credit: | Roi Mallo and Sherab Giovannini working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
Apple QuickTime Player 7.6.8 Apple QuickTime Player 7.6.7 Apple QuickTime Player 7.6.6 (1671) Apple QuickTime Player 7.6.6 Apple QuickTime Player 7.6.5 Apple QuickTime Player 7.6.4 Apple QuickTime Player 7.6.2 Apple QuickTime Player 7.6.1 Apple QuickTime Player 7.5.5 Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.64.17.73 Apple QuickTime Player 7.6.9 Apple QuickTime Player 7.6 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 |
| Not Vulnerable: |
Apple QuickTime Player 7.7 |
Discussion
Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
Apple QuickTime is prone to multiple stack-based buffer-overflow vulnerabilities because of a failure to properly bounds-check user-supplied data.
Successful exploits will allow attackers to execute arbitrary code in the context of the currently logged-in user; failed exploit attempts may cause denial-of-service conditions.
Versions prior to QuickTime 7.7 are vulnerable.
NOTE: These issues were previously discussed in BID 48993 (Apple QuickTime Prior To 7.7 Multiple Arbitrary Code Execution Vulnerabilities) but has been given their own record to better document them.
Apple QuickTime is prone to multiple stack-based buffer-overflow vulnerabilities because of a failure to properly bounds-check user-supplied data.
Successful exploits will allow attackers to execute arbitrary code in the context of the currently logged-in user; failed exploit attempts may cause denial-of-service conditions.
Versions prior to QuickTime 7.7 are vulnerable.
NOTE: These issues were previously discussed in BID 48993 (Apple QuickTime Prior To 7.7 Multiple Arbitrary Code Execution Vulnerabilities) but has been given their own record to better document them.
Exploit / POC
Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Apple QuickTime Player 7.6
Apple QuickTime Player 7.6.9
Apple QuickTime Player 7.6.1
Apple QuickTime Player 7.6.2
Apple QuickTime Player 7.6.4
Apple QuickTime Player 7.6.5
Apple QuickTime Player 7.6.6
Apple QuickTime Player 7.6.6 (1671)
Apple QuickTime Player 7.6.7
Apple QuickTime Player 7.6.8
Solution:
Vendor updates are available. Please see the references for more information.
Apple QuickTime Player 7.6
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.9
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.1
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.2
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.4
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.5
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.6
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.6 (1671)
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.7
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.8
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
References
Apple QuickTime CVE-2011-0247 H.264 Movie Files Multiple Buffer Overflow Vulnerabilities
References:
References:
- Apple QuickTime Homepage (Apple)
- Apple QuickTime Player H.264 Reference Picture List Remote Code Execution Vulner (TippingPoint Zero Day Initiative)
- Apple QuickTime Player H.264 Slice Header Remote Code Execution Vulnerability (TippingPoint Zero Day Initiative)