Apple QuickTime Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.
1. A heap overflow error when handling malformed RTSP URLs, which could be exploited to crash an affected application or execute arbitrary code via a malicious URL.
2. A heap overflow error when handling malformed THKD atoms in QTVR (QuickTime Virtual Reality) movie files, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.
3. A heap overflow error when processing a malformed "nBlockAlign" value in the "_WAVEFORMATEX" structure of an AVI file, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.
4. A buffer overflow error when handling malformed MPEG-2 video files with MP3 audio content, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.
5. A memory corruption error when handling malformed H.263 encoded movie files, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.
6. A signedness error when handling Cinepak encoded movie files, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.
7. A heap overflow error in the handling of JPEG atoms embedded in STSD atoms within the "JPEG_DComponentDispatch()" function, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.
8. An input validation error when processing malformed MPEG-2 files, which may allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious movie file.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- QuickTime versions prior to 7.6
- QuickTime MPEG-2 Playback Component for Windows versions prior to 7.60.92.0
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to QuickTime version 7.6 :
http://www.apple.com/quicktime/download/
- Upgrade to QuickTime MPEG-2 Playback Component for Windows version 7.60.92.0 :
http://www.apple.com/quicktime/mpeg2/
Vulnerability Identifier
- CVE-2009-0001
- CVE-2009-0002
- CVE-2009-0003
- CVE-2009-0004
- CVE-2009-0005
- CVE-2009-0006
- CVE-2009-0007
- CVE-2009-0008
Source
Related Link
Share with