Apple 'quicktime.qts' Error in Parsing 'qtif' Images Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1012991
|
|
SecurityTracker URL: http://securitytracker.com/id?1012991
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Jan 25 2005
|
Impact: Denial of service via network
|
Exploit Included: Yes
|
Version(s): 6.5.2.10 and prior
|
Description: ATmaCA reported a vulnerability in Apple QuickTime in the 'quicktime.qts' component. A remote user can cause the target user's QuickTime viewer to crash.
A remote user can create a specially crafted 'qtif' image file with an incomplete header that, when viewed by the target user, will
cause the target user's browser or QuickTime viewer to crash.
A demonstration exploit header is available at:
http://www.atmacasoft.com/exp/vuln.qtif.zip
The
vendor has been notified without response.
|
Impact: A remote user can cause the target user's browser or QuickTime viewer to crash.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.apple.com/quicktime/ (Links to External Site)
|
Cause: Exception handling error
|
Underlying OS: Windows (Any)
|
Reported By: atmaca <atmaca@atmacasoft.com>
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 24 Jan 2005 13:36:05 +0200
From: atmaca <atmaca@atmacasoft.com>
Subject: Apple QuickTime (.qtif) image Parsing Vulnerability
|
Application: QuickTime
http://www.apple.com/quicktime/
AFFECTED VERSION:
Versions verified to be vulnerable:
QuickTime.qts (6.5.2.10) and prior versions are affected.
The bug:
The problem specifically exists when QuickTime.qts component parsing
(.qtif) image files that contain uncompleted header.
A remote user can create a file that when processed by QuickTime PictureViewer or via browser,
will can cause the remote system to crash.
--Uncompleted qtif image file header
http://www.atmacasoft.com/exp/vuln.qtif.zip
00000000 0000 005E 6964 7363 0000 0056 6A70 6567 0000 0000 0000 0000 0000 0000 ...^idsc...Vjpeg...... ......
0000001C 6170 706C 0000 0000 0000 0200 0100 016D 0048 0000 0048 0000 0000 724D appl...........m.H...H ....rM
00000038 0001 0C50 686F 746F 202D 204A 5045 4700 0000 0000 0000 0000 0000 0000 ...Photo - JPEG....... ......
00000054 0000 0000 0000 0018 FFFF 0000 7255 6964 6174 FFD8 FFE0 0010 ............rUidat.... ..
VENDOR RESPONSE:
No vendor response.
Discoveried By ATmaCA
AtmacaSoft Inc.
http://www.atmacasoft.com
|
|