Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Fw: iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows QuickTime Pl



hi folks

FYI a iDEFENSE Security Advisory 03.31.03: Buffer Overflow in Windows
QuickTime Player

best bob
p.s. sorry for 2. mailing if yout now all reday.

form http://www.idefense.com/advisory/03.31.03.txt
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

iDEFENSE Security Advisory 03.31.03:
http://www.idefense.com/advisory/03.31.03.txt
Buffer Overflow in Windows QuickTime Player
March 31, 2003

I. BACKGROUND

QuickTime Player is a popular media player for both the Microsoft Windows
and Apple Mac platforms.  More information about the application is
available at http://www.apple.com/quicktime/ .

II. DESCRIPTION

An exploitable buffer overflow condition has been discovered in Apple
Computer Inc.'s QuickTime Player, allowing for the remote execution of
arbitrary code. The vulnerability lies in the processing of long
QuickTime
URL's (quicktime:// or through the -u switch). When processing a
QuickTime
URL, the application is launched in the following manner as can be seen
from the Windows registry key HKEY_CLASSES_ROOT/quicktime:

%PATH TO QUICKTIME%\QuickTimePlayer.exe -u"%1"

A URL containing 400 characters will overrun the allocated space on the
stack overwriting the saved instruction pointer (EIP). This will thereby
allow an attacker to redirect the flow of control. An example URL that
will cause QuickTime player to crash is:

quicktime://127.0.0.1/AAAA...

Where the character 'A' is repeated 400 times.

III. ANALYSIS

Any remote attacker can compromise a target system if he or she can
convince a user to load a specially crafted exploit URL.  Upon successful
exploitation, arbitrary code can be executed under the privileges of the
user who launched QuickTime.

IV. DETECTION

iDEFENSE has confirmed that QuickTime Player versions 5.x and 6.0 for the
Microsoft Windows platform are vulnerable. QuickTime for MacOS is not
vulnerable.

V. WORKAROUND

Removing the QuickTime handler from the web browser or removing the
registry key HKEY_CLASSES_ROOT/quicktime can prevent automatic
exploitation through HTML pages.

VI. VENDOR FIX

Apple has released QuickTime 6.1 which addresses this vulnerability.  It
is available from http://www.apple.com/quicktime/download/ .

VII. CVE INFORMATION

The Mitre Corp.'s Common Vulnerabilities and Exposures (CVE) Project
assigned the identification number CAN-2003-0168 to this issue.

VIII. DISCLOSURE TIMELINE

01/16/2003      Issue disclosed to iDEFENSE
02/24/2003      iDEFENSE notification sent to email@hidden
02/24/2003      Response received from Apple Product Security team
02/24/2003      iDEFENSE clients notified
03/31/2003      Coordinated Public disclosure

IX. CREDIT

Texonet (http://www.texonet.com) is credited with discovering this
vulnerability.

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0

iQA/AwUBPojVyvrkky7kqW5PEQKG7ACgr2mSx0KxnnisrosIJSzr7BfUNEkAoMh0
uPz5fkgQN/aj5TXzVLf25LcN
=/e6O
-----END PGP SIGNATURE-----


--
from
http://www.heise.de/bin/nt.print/newsticker/data/see-02.04.03-001/?id=b9f8488c&todo=print

Heise News:
Quicktime und Real Player sind nicht ganz "dicht"
[02.04.2003 18:12 ]

Die beiden Media-Player Quicktime und Real Player weisen Sicherheitsl|cken
auf. So hat die US-amerikanische Sicherheitsberatungsfirma iDefense[1]
einen
"Buffer Overflow" bei den Windows-Versionen 5.x und 6.0 des Quicktime
Players festgestellt. Dieser entsteht, wenn Web-Adressen mit mehr als 400
Zeichen
mit Quicktime aufgerufen werden. Eine genaue Beschreibung des Problems
findet man in dem Security Advisory[2] von iDefense. In diesem Advisory
befindet
sich auch ein Workaround zum Schlie_en dieser L|cke. Eine andere
Mvglichkeit ist das Update auf die Version 6.1 von Quicktime; hier sollen
diese
Schwachstellen laut iDefense nicht mehr auftreten.

Ebenfalls nicht ganz "dicht" sind RealOne Player, RealOne Player v2 f|r
Windows, RealPlayer 8 f|r Windows, RealPlayer 8 f|r Mac OS 9, RealOne
Player f|r
Mac OS X, RealOne Enterprise Desktop Manager und RealOne Enterprise Desktop
(alle Versionen) von Real Networks[3]. Das Unternehmen warnt davor,
dass sich Angreifer durch speziell prdparierte PNG-Grafikdateien (Portable
Network Graphics) einen Zugang zum Computer verschaffen kvnnen. Auch
dieses
Problem kann mit einem Update[4] behoben werden. (see[5]/c't)


URL dieses Artikels:
  http://www.heise.de/newsticker/data/see-02.04.03-001/

Links in diesem Artikel:
  [1] http://www.idefense.com
  [2] http://www.idefense.com/advisory/03.31.03.txt
  [3] http://www.real.com
  [4]
http://service.real.com/help/faq/security/securityupdate_march2003.html
  [5] mailto:email@hidden


Copyright 2003 by Heise Zeitschriften Verlag





--- END OF FORWARDED MESSAGE ------------------------------------------------Wolfgang

3600 und zur|ck. Wir machen es mvglich.
          http://www.maxVR.de
_______________________________________________
quicktime-vr mailing list | email@hidden
Help/Unsubscribe/Archives: http://www.lists.apple.com/mailman/listinfo/quicktime-vr
Do not post admin requests to the list. They will be ignored.



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.