SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Multimedia)  >  QuickTime Vendors:  Apple Computer
Apple 'quicktime.qts' Error in Parsing 'qtif' Images Lets Remote Users Deny Service
SecurityTracker Alert ID:  1012991
SecurityTracker URL:  http://securitytracker.com/id?1012991
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Jan 25 2005
Impact:  Denial of service via network
Exploit Included:  Yes  
Version(s): 6.5.2.10 and prior
Description:  ATmaCA reported a vulnerability in Apple QuickTime in the 'quicktime.qts' component. A remote user can cause the target user's QuickTime viewer to crash.

A remote user can create a specially crafted 'qtif' image file with an incomplete header that, when viewed by the target user, will cause the target user's browser or QuickTime viewer to crash.

A demonstration exploit header is available at:

http://www.atmacasoft.com/exp/vuln.qtif.zip

The vendor has been notified without response.

Impact:  A remote user can cause the target user's browser or QuickTime viewer to crash.
Solution:  No solution was available at the time of this entry.
Vendor URL:  www.apple.com/quicktime/ (Links to External Site)
Cause:  Exception handling error
Underlying OS:  Windows (Any)
Reported By:  atmaca <atmaca@atmacasoft.com>
Message History:   None.


 Source Message Contents

Date:  Mon, 24 Jan 2005 13:36:05 +0200
From:  atmaca <atmaca@atmacasoft.com>
Subject:  Apple QuickTime (.qtif) image Parsing Vulnerability

 
 
Application: QuickTime
             http://www.apple.com/quicktime/
 
AFFECTED VERSION:
Versions verified to be vulnerable:
QuickTime.qts (6.5.2.10) and prior versions are affected.
 
The bug:	
The problem specifically exists when QuickTime.qts component parsing 
(.qtif) image files that contain uncompleted header.
A remote user can create a file that when processed by QuickTime PictureViewer or via browser, 
will can cause the remote system to crash.
 
--Uncompleted qtif image file header
http://www.atmacasoft.com/exp/vuln.qtif.zip
 
00000000 0000 005E 6964 7363 0000 0056 6A70 6567 0000 0000 0000 0000 0000 0000 ...^idsc...Vjpeg......
...... 0000001C 6170 706C 0000 0000 0000 0200 0100 016D 0048 0000 0048 0000 0000 724D appl...........m.H...H
....rM 00000038 0001 0C50 686F 746F 202D 204A 5045 4700 0000 0000 0000 0000 0000 0000 ...Photo - JPEG.......
...... 00000054 0000 0000 0000 0018 FFFF 0000 7255 6964 6174 FFD8 FFE0 0010 ............rUidat....
.. VENDOR RESPONSE: No vendor response. Discoveried By ATmaCA AtmacaSoft Inc. http://www.atmacasoft.com


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2004, SecurityGlobal.net LLC