Skip to main content

Apple QuickTime Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 23 Jan 2009 4722 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Apple QuickTime, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system.

1. A heap overflow error when handling malformed RTSP URLs, which could be exploited to crash an affected application or execute arbitrary code via a malicious URL.

2. A heap overflow error when handling malformed THKD atoms in QTVR (QuickTime Virtual Reality) movie files, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.

3. A heap overflow error when processing a malformed "nBlockAlign" value in the "_WAVEFORMATEX" structure of an AVI file, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.

4. A buffer overflow error when handling malformed MPEG-2 video files with MP3 audio content, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.

5. A memory corruption error when handling malformed H.263 encoded movie files, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.

6. A signedness error when handling Cinepak encoded movie files, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.

7. A heap overflow error in the handling of JPEG atoms embedded in STSD atoms within the "JPEG_DComponentDispatch()" function, which could be exploited to execute arbitrary code by tricking a user into opening a specially crafted movie file.

8. An input validation error when processing malformed MPEG-2 files, which may allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious movie file.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • QuickTime versions prior to 7.6
  • QuickTime MPEG-2 Playback Component for Windows versions prior to 7.60.92.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link