Apple QuickTime Multiple Vulnerabilities
Secunia Advisory: SA28502
Release Date: 2008-01-16
Critical:
Highly critical
Impact: System access
Where: From remote
Solution Status:
Vendor Patch
Software: Apple QuickTime 7.x
CVE reference:
CVE-2008-0031 (Secunia mirror)
CVE-2008-0032 (Secunia mirror)
CVE-2008-0033 (Secunia mirror)
CVE-2008-0036 (Secunia mirror)
Description:
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a vulnerable system.
1) An unspecified error exists in the handling of Sorenson 3 video files, which can be exploited to cause a memory corruption and may allow execution of arbitrary code.
2) An error exists in the processing of Macintosh Resources embedded in QuickTime movies. This can be exploited to cause a memory corruption via an overly large length value stored in the resource header in a specially crafted QuickTime movie file.
3) An error in the parsing of malformed Image Descriptor (IDSC) atoms can be exploited to cause a heap corruption via a specially crafted movie file.
4) A boundary error exists within the processing of compressed PICT images and can be exploited to cause a buffer overflow.
Successful exploitation of these vulnerabilities may allow execution of arbitrary code.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector or Online Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Solution:
Update to QuickTime 7.4
Bollettino di Sicurezza