Executive Summary

Summary
Title Apple QuickTime Updates for Multiple Vulnerabilities
Informations
Name TA08-016A First vendor Publication 2008-01-16
Vendor US-CERT Last vendor Modification 2008-01-16
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Apple QuickTime contains multiple vulnerabilities. Exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

I. Description

Apple QuickTime 7.4 resolves multiple vulnerabilities in the way different types of image and media files are handled. An attacker could exploit these vulnerabilities by convincing a user to access a specially crafted image or media file that could be hosted on a web page.

Note that Apple iTunes installs QuickTime, so any system with iTunes is vulnerable.

II. Impact

These vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition. For further information, please see About the security content of QuickTime 7.4.

III. Solution

Upgrade QuickTime

Upgrade to QuickTime 7.4. This and other updates for Mac OS X are available via Apple Update.

Secure your web browser

To help mitigate these and other vulnerabilities that can be exploited via a web browser, refer to Securing Your Web Browser.

Original Source

Url : http://www.us-cert.gov/cas/techalerts/TA08-016A.html

CWE : Common Weakness Enumeration

% Id Name
75 % CWE-399 Resource Management Errors
25 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 191

Open Source Vulnerability Database (OSVDB)

Id Description
40898 Apple QuickTime PICT Image Decompression Overflow

40897 Apple QuickTime Movie File Malformed Image Descriptor (IDSC) Memory Corruptio...

40896 Apple QuickTime Movie File Malformed Macintosh Resource Record Heap Corruptio...

40895 Apple QuickTime Sorenson 3 Video Handling Memory Corruption Arbitrary Code Ex...

Snort® IPS/IDS

Date Description
2014-01-10 Apple Quicktime malformed idsc atom
RuleID : 13517 - Revision : 12 - Type : FILE-MULTIMEDIA

Nessus® Vulnerability Scanner

Date Description
2008-01-16 Name : The remote Mac OS X host contains an application that is affected by multiple...
File : macosx_Quicktime74.nasl - Type : ACT_GATHER_INFO
2008-01-16 Name : The remote Windows host contains an application that is affected by multiple ...
File : quicktime_74.nasl - Type : ACT_GATHER_INFO