SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Multimedia)  >   QuickTime Vendors:   Apple Computer
(Apple Issues Fix for QuickTime) Apple QuickTime Multiple Bugs Let Remote Users Execute Arbitrary
SecurityTracker Alert ID:  1025887
SecurityTracker URL:  http://securitytracker.com/id/1025887
CVE Reference:   CVE-2011-0209, CVE-2011-0210, CVE-2011-0211, CVE-2011-0213   (Links to External Site)
Date:  Aug 4 2011
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  

Description:   A vulnerability was reported in QuickTime. A remote user can cause arbitrary code to be executed on the target user's system.

A remote user can create a specially crafted file that, when loaded by the target user, will execute arbitrary code on the target system. The code will run with the privileges of the target user.

A specially crafted RIFF WAV file can trigger an integer overflow [CVE-2011-0209]. Luigi Auriemma reported this vulnerability via TippingPoint's Zero Day Initiative.

Specially crafted sample tables in a QuickTime movie file can cause code execution [CVE-2011-0210]. Honggang Ren of Fortinet's FortiGuard Labs reported this vulnerability.

A specially crafted movie file can trigger an integer overflow [CVE-2011-0211]. Luigi Auriemma reported this vulnerability via TippingPoint's Zero Day Initiative.

A specially crafted JPEG file can trigger a buffer overflow [CVE-2011-0213]. Luigi Auriemma reported this vulnerability via iDefense.

Impact:   A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution:   Apple has issued a fix for QuickTime (7.7), available from the Software Update application, or from the QuickTime Downloads site at:

http://www.apple.com/quicktime/download/

For Mac OS X v10.5.8
The download file is named: "QuickTime77Leopard.dmg"
Its SHA-1 digest is: 0deb99cc44015af7c396750d2c9dd4cbd59fb355

For Windows 7 / Vista / XP SP3
The download file is named: "QuickTimeInstaller.exe"
Its SHA-1 digest is: a99f61d67be6a6b42e11d17b0b4f25cd88b74dc9

The Apple advisory is available at:

http://support.apple.com/kb/HT4826

Vendor URL:  support.apple.com/kb/HT4723 (Links to External Site)
Cause:   Access control error, Boundary error
Underlying OS:   UNIX (OS X), Windows (7), Windows (Vista), Windows (XP)

Message History:   This archive entry is a follow-up to the message listed below.
Jun 24 2011 Apple QuickTime Multiple Bugs Let Remote Users Execute Arbitrary



 Source Message Contents

Date:  Thu, 04 Aug 2011 18:51:08 +0000
Subject:  Apple QuickTime


APPLE-SA-2011-08-03-1 QuickTime 7.7

CVE-2011-0209
CVE-2011-0210
CVE-2011-0211
CVE-2011-0213
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC