Unsolved

This post is more than 5 years old

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

5891

November 11th, 2010 04:00

NOW patched: Quicktime Player "Sorenson Video 3 array-indexing" vulnerability

the following has been copied/pasted from http://secunia.com/advisories/39259/

Description
Secunia Research has discovered a [highly critical] vulnerability in QuickTime, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an array-indexing error when parsing Sorenson Video 3 content and can be exploited to corrupt memory during decompression via a specially crafted file.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is confirmed in versions 7.6.6 and 7.6.8. Other versions may also be affected.

Solution
This will be addressed in an upcoming version for Windows.  A fix is available for Mac OS X.

Provided and/or discovered by
Carsten Eiram, Secunia Research.

The vendor also credits an anonymous person via ZDI.

Original Advisory
Apple:
http://support.apple.com/kb/HT4435

 

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

December 8th, 2010 05:00

Patched version (7.6.9) now released.

The above Secunia advisory has been expanded (in detail), as follows:

Description
Multiple [highly critical] vulnerabilities have been reported in QuickTime, which can be exploited by malicious, local users to disclose potentially sensitive information or manipulate certain data, and by malicious people to compromise a user's system.

1) An array-indexing error when parsing the extra data bits in Sorenson Video 3 content can be exploited to cause a value outside an array of pointers to erroneously be used as a write pointer during decompression.

The vulnerability is confirmed in versions 7.6.6 and 7.6.8. Other versions may also be affected.

2) An error when parsing "rec" chunks within AVI files can be exploited to corrupt memory.

3) An uninitialised pointer error in the support for Huffman tables within FlashPix files can be exploited to use an invalid value as a destination pointer when copying data.

4) An input validation error in the support for a component within the "SIZ" marker in a JPEG 2000 image can be exploited to use uninitialised data as an object during decompression.

5) An input validation error in the LZW decompression of GIF images can be exploited to cause a heap-based buffer overflow.

6) An input validation error in QuickTimeMPEG.qtx when parsing the media rate field of an "ELST" atom's edit list table data can be exploited to corrupt memory.

7) A signedness error in quicktime.qtx when parsing a certain offset in a "m1s" atom can be exploited to corrupt memory.

8) An type confusion error in QuickTime within the processing of JP2 codestreams can be exploited to cause a heap-based buffer overflow, which may allow execution of arbitrary code when a specially crafted JP2 image is being viewed.

9) An unspecified error in QuickTime may allow execution of arbitrary code.

For more information see vulnerability #43 in:
SA42151

10) Input validation errors in the Quicktime PictureViewer when processing a PICT file can be exploited to e.g. cause a buffer overflow.

11) An input validation error in the processing of length properties in FlashPix images can be exploited to corrupt memory.

12) An signedness error in the handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files can be exploited to trigger the usage of an invalid pointer and corrupt memory.

13) A security issue is caused due to the application creating the "%UserProfile%\Local Settings\Application Data\Apple Computer\" directory with insecure default permissions. This can be exploited by unprivileged users to write or read from potentially sensitive files placed inside the affected directory by e.g. Safari.

14) An integer overflow error the handling of movie files can be exploited to corrupt memory.

15) A boundary error when copying track content based on the track's dimensions can be exploited to cause a heap-based buffer overflow.

Successful exploitation of the vulnerabilities may allow execution of arbitrary code.

Solution
Update to version 7.6.9.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

December 8th, 2010 12:00

I have applied the "vendor workaround" to IE8 --- the user-defined style sheet [which was far more simple to implement than I had originally understood] --- as well as invoking EMET... so I take that to me I'm protected from the "highly critical" vulnerability.   [Apparently Secunia's PSI does not check for the work-around.]

(It's possible that Microsoft may release an official patch for this next week, on Tuesday).

 

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

December 8th, 2010 12:00

Thanks for that, ky.

Now 2 of my 4 browsers are fully patched and secure: Opera 10.x and Firefox 3.6.x.

- Safari 5.x still has one "less critical" unpatched vulnerability: http://secunia.com/advisories/40110/


- IE8.0.x has one "highly critical" unpatched vulnerability: http://secunia.com/advisories/42091/ , albeit with a vendor workaround: http://www.microsoft.com/technet/security/advisory/2458511.mspx

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

December 10th, 2010 05:00

Just confirmed that Microsoft will indeed be releasing a patch for that vulnerabilty this coming Tuesday, 12/14

http://www.facebook.com/notes/microsoft-malware-protection-center/cve-2010-3962-the-weekend-warrior/475611313925

No Events found!

Top