This application requires Javascript for optimal performance.

Apple.Quicktime.Multiple.Vuln

Alias(es)

Apple.QuickTime.StripByteCounts.Buffer.Overflow, Apple.QuickTime.StripOffsets.Improper.Memory.Access, Apple.Quicktime.ImageWidth.DoS

Release Date

Jan 16, 2006

Severity

low

Impact

System compromise.

Description

A vulnerability in Apple QuickTime may allow system compromise. The vulnerability is due to a boundry condition error when the application handles specially crafted QTIF, TGA, TIFF, and GIF image formats. An integer overflow allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags. Successful exploitation may allow a remote attacker to trigger a denial of service condition or gain unauthorized access.

Affected Products

Apple QuickTime Player 7.0.3


Apple QuickTime Player 7.0.2


Apple QuickTime Player 7.0.1


Apple QuickTime Player 7.0


Recommended Actions

Apple has released advisory APPLE-SA-2006-01-10 including QuickTime 7.0.4 to address these issues.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-3710
CVE-2005-3711

Reference/s

http://docs.info.apple.com/article.html?artnum=303101
http://www.securityfocus.com/bid/16202 (BugTraq)

Reference: VID-11624