Apple QuickTime PICT File CVE-2011-0257 Stack Buffer Overflow Vulnerability
BID:49144
Info
Apple QuickTime PICT File CVE-2011-0257 Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 49144 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-0257 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2011 12:00AM |
| Updated: | Sep 05 2011 08:30AM |
| Credit: | Matt 'j00ru' Jurczyk working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
Apple QuickTime Player 7.6.8 Apple QuickTime Player 7.6.7 Apple QuickTime Player 7.6.6 (1671) Apple QuickTime Player 7.6.6 Apple QuickTime Player 7.6.5 Apple QuickTime Player 7.6.4 Apple QuickTime Player 7.6.2 Apple QuickTime Player 7.6.1 Apple QuickTime Player 7.5.5 Apple QuickTime Player 7.4.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.64.17.73 Apple QuickTime Player 7.6.9 Apple QuickTime Player 7.6 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 |
| Not Vulnerable: |
Apple QuickTime Player 7.7 |
Discussion
Apple QuickTime PICT File CVE-2011-0257 Stack Buffer Overflow Vulnerability
Apple QuickTime is prone to a stack-based buffer-overflow vulnerability because of a failure to properly bounds check user-supplied data.
Successful exploits will allow attackers to execute arbitrary code in the context of the currently logged-in user; failed exploit attempts may cause denial-of-service conditions.
Versions prior to QuickTime 7.7 are vulnerable.
Apple QuickTime is prone to a stack-based buffer-overflow vulnerability because of a failure to properly bounds check user-supplied data.
Successful exploits will allow attackers to execute arbitrary code in the context of the currently logged-in user; failed exploit attempts may cause denial-of-service conditions.
Versions prior to QuickTime 7.7 are vulnerable.
Exploit / POC
Apple QuickTime PICT File CVE-2011-0257 Stack Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Apple QuickTime PICT File CVE-2011-0257 Stack Buffer Overflow Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Apple QuickTime Player 7.6
Apple QuickTime Player 7.6.9
Apple QuickTime Player 7.6.1
Apple QuickTime Player 7.6.2
Apple QuickTime Player 7.6.4
Apple QuickTime Player 7.6.5
Apple QuickTime Player 7.6.6
Apple QuickTime Player 7.6.6 (1671)
Apple QuickTime Player 7.6.7
Apple QuickTime Player 7.6.8
Solution:
Vendor updates are available. Please see the references for more information.
Apple QuickTime Player 7.6
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.9
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.1
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.2
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.4
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.5
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.6
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.6 (1671)
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.7
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
Apple QuickTime Player 7.6.8
-
Apple APPLE-SA-2011-08-03-1-QuickTimeInstaller.exe
For Windows 7 / Vista / XP SP3
http://www.apple.com/quicktime/download/ -
Apple QuickTime77Leopard.dmg
For Mac OS X v10.5.8
http://www.apple.com/quicktime/download/
References
Apple QuickTime PICT File CVE-2011-0257 Stack Buffer Overflow Vulnerability
References:
References:
- Apple QuickTime Homepage (Apple)
- QuickTime 7.7 (Apple)
- Apple QuickTime PICT Image PnSize Opcode Remote Code Execution Vulnerability (TippingPoint Zero Day Initiative)