On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

September 9th, 2008

Apple plugs gaping QuickTime security holes

Posted by Ryan Naraine @ 2:05 pm

Categories: Apple, Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Passwords, Patch Watch, Pen testing, Vulnerability research, Web Applications, Zero-day attacks, iPhone

Tags: Security, Apple Macintosh, Apple QuickTime, Microsoft Windows XP, Service Pack 2, Movie, SP3, Microsoft Windows Vista, Apple Inc., Arbitrary Code Execution

Code execution holes haunt QuickTimeApple today released a major makeover to its iTunes and QuickTime software products, fixing at least 11 documented security vulnerabilities that could lead to Mac and PC takeover attacks.

QuickTime 7.5.5, which should be considered an “extremely critical” update, address nine different vulnerabilities that could cause some serious damage if a Windows or Mac OS X user is tricked into viewing a rigged movie file. The iTunes 8 update addresses two separate bugs that could put users at risk of information disclosure.

Full details on the vulnerabilities and patches:

QUICKTIME 7.5.5

  • CVE-2008-3615: An uninitialized memory access issue exists in the third-party Indeo v5 codec for QuickTime, which does not ship with QuickTime. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Affects Windows Vista, XP SP2 and SP3
  • CVE-2008-3635: A stack buffer overflow exists in the third-party Indeo v3.2 codec for QuickTime. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution.  Affects Windows Vista, XP SP2 and SP3.
  • CVE-2008-3624: A heap buffer overflow exists in QuickTime’s handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR file may lead to an unexpected application termination or arbitrary code execution.  Affects Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3.
  • CVE-2008-3625: A stack buffer overflow exists in QuickTime’s handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR file may lead to an unexpected application termination or arbitrary code execution.
    Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3614: An integer overflow exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution. Affects Windows Vista, XP SP2 and SP3.
  • CVE-2008-3626:  A memory corruption issue exists in QuickTime’s handling of STSZ atoms in movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution.  Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3627: Multiple memory corruption exist in QuickTime’s handling of H.264 encoded movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. Available for Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3
  • CVE-2008-3628: An invalid pointer issue exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution. Available for Windows Vista, XP SP2 and SP3.
  • CVE-2008-3629: An out-of-bounds read issue exists in QuickTime’s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination. Affects Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3.

iTunes 8

  • CVE-2008-3634: When the firewall is configured to block iTunes Music Sharing and the user enables iTunes Music Sharing in iTunes, a warning dialog is displayed which incorrectly informs the user that unblocking iTunes Music Sharing doesn’t affect the firewall’s
    security. Allowing iTunes Music Sharing or any other service through the firewall inherently affects security by exposing the service to
    remote entities. This update addresses the issue by refining the text in the warning dialog. Available for Mac OS X v10.4.11, Mac OS X Server v10.4.11.
  • CVE-2008-3636: A third-party driver provided with iTunes may trigger an integer overflow, and could allow a local user to obtain system privileges.  Available for:  Windows XP or Vista.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 22 Talkback(s)
Building a solid house...
on top of the garbage dump of Windows might
well cause problems. Even so, wake me when the
first 1000+ Windows PCs are made into a botnet
because of arcane bugs in quicktime. Notice that <... (Read the rest)
Posted by: arminw Posted on: 09/22/08 You are currently: a Guest | | Terms of Use
Looks to me Quicktime has been put through a code  Richard Flude | 09/09/08
Don't think so  tonymcs@... | 09/09/08
You're right  Richard Flude | 09/09/08
If they haven't already  mdemuth | 09/09/08
New tools becoming available all the time  Richard Flude | 09/09/08
Wow, that's a lot of critical vulnerabilities  NonZealot | 09/09/08
Securing iTunes requires upgrading to 8?  PB_z | 09/09/08
Difference with iTunes 8...  ExCorpGuy | 09/10/08
How many people have complained about the "Free" IE7 update?  PB_z | 09/10/08
The problem with IE7  lumpy_blumpkin | 09/10/08
Wait....Look at this  laura.b | 09/10/08
I banned QuickTime from my Windows  qmlscycrajg | 09/10/08
MOV is a good container format  brunerd | 09/10/08
I've said it before, don't run with administrative rights  betelgeuse68 | 09/10/08
Quicktime is garbage.  TripleII | 09/10/08
Quicktime X  brunerd | 09/10/08
Good info, thanks. It will be massively proprietary.  TripleII | 09/10/08
Building a solid house...  arminw | 09/22/08
RE: Apple plugs gaping QuickTime security holes  jimboutilier@... | 09/10/08
Double Standard?  KaplanMike | 09/10/08
Curious eh?  isulzer | 09/11/08
RE: Apple plugs gaping QuickTime security holes  mjburns@... | 09/10/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline