exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

iDEFENSE Security Advisory 2003-03-31.t

iDEFENSE Security Advisory 2003-03-31.t
Posted Apr 1, 2003
Authored by iDefense Labs | Site idefense.com

iDEFENSE Security Advisory 03.31.03 - An exploitable buffer overflow has been found in Apple Computer's QuickTime Player v5.x and 6.0 which allows the remote execution of arbitrary code via long quicktime:// URL's or the -u command line switch. Any remote attacker can compromise a target system if he or she can convince a user to load a specially crafted exploit URL. Upon successful exploitation, arbitrary code can be executed under the privileges of the user who launched QuickTime.

tags | advisory, remote, overflow, arbitrary
systems | apple
SHA-256 | 63b4e5946d2c0800bdcb621548d55499d68e76124dd328d5ff058b472234203b

iDEFENSE Security Advisory 2003-03-31.t

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

iDEFENSE Security Advisory 03.31.03:
http://www.idefense.com/advisory/03.31.03.txt
Buffer Overflow in Windows QuickTime Player
March 31, 2003

I. BACKGROUND

QuickTime Player is a popular media player for both the Microsoft Windows
and Apple Mac platforms. More information about the application is
available at http://www.apple.com/quicktime/ .

II. DESCRIPTION

An exploitable buffer overflow condition has been discovered in Apple
Computer Inc.'s QuickTime Player, allowing for the remote execution of
arbitrary code. The vulnerability lies in the processing of long QuickTime
URL's (quicktime:// or through the -u switch). When processing a QuickTime
URL, the application is launched in the following manner as can be seen
from the Windows registry key HKEY_CLASSES_ROOT/quicktime:

%PATH TO QUICKTIME%\QuickTimePlayer.exe -u"%1"

A URL containing 400 characters will overrun the allocated space on the
stack overwriting the saved instruction pointer (EIP). This will thereby
allow an attacker to redirect the flow of control. An example URL that
will cause QuickTime player to crash is:

quicktime://127.0.0.1/AAAA...

Where the character 'A' is repeated 400 times.

III. ANALYSIS

Any remote attacker can compromise a target system if he or she can
convince a user to load a specially crafted exploit URL. Upon successful
exploitation, arbitrary code can be executed under the privileges of the
user who launched QuickTime.

IV. DETECTION

iDEFENSE has confirmed that QuickTime Player versions 5.x and 6.0 for the
Microsoft Windows platform are vulnerable. QuickTime for MacOS is not
vulnerable.

V. WORKAROUND

Removing the QuickTime handler from the web browser or removing the
registry key HKEY_CLASSES_ROOT/quicktime can prevent automatic
exploitation through HTML pages.

VI. VENDOR FIX

Apple has released QuickTime 6.1 which addresses this vulnerability. It
is available from http://www.apple.com/quicktime/download/ .

VII. CVE INFORMATION

The Mitre Corp.'s Common Vulnerabilities and Exposures (CVE) Project
assigned the identification number CAN-2003-0168 to this issue.

VIII. DISCLOSURE TIMELINE

01/16/2003 Issue disclosed to iDEFENSE
02/24/2003 iDEFENSE notification sent to product-security@apple.com
02/24/2003 Response received from Apple Product Security team
02/24/2003 iDEFENSE clients notified
03/31/2003 Coordinated Public disclosure

IX. CREDIT

Texonet (http://www.texonet.com) is credited with discovering this
vulnerability.

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0

iQA/AwUBPojVyvrkky7kqW5PEQKG7ACgr2mSx0KxnnisrosIJSzr7BfUNEkAoMh0
uPz5fkgQN/aj5TXzVLf25LcN
=/e6O
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close