Vulnerabilities > CVE-2008-3614 - Numeric Errors vulnerability in Apple Quicktime

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
apple
microsoft
CWE-189
nessus

Summary

Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, which triggers heap corruption.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyWindows
    NASL idQUICKTIME_755.NASL
    descriptionThe version of QuickTime installed on the remote Windows host is older than 7.5.5. Such versions contain several vulnerabilities : - An integer overflow in QuickTime
    last seen2020-06-01
    modified2020-06-02
    plugin id34119
    published2008-09-10
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/34119
    titleQuickTime < 7.5.5 Multiple Vulnerabilities (Windows)
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_SECUPD2008-006.NASL
    descriptionThe remote host is running a version of Mac OS X 10.4 that does not have the security update 2008-006 applied. This update contains security fixes for a number of programs.
    last seen2020-06-01
    modified2020-06-02
    plugin id34210
    published2008-09-16
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/34210
    titleMac OS X Multiple Vulnerabilities (Security Update 2008-006)
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_10_5_5.NASL
    descriptionThe remote host is running a version of Mac OS X 10.5.x that is prior to 10.5.5. Mac OS X 10.5.5 contains security fixes for a number of programs.
    last seen2020-06-01
    modified2020-06-02
    plugin id34211
    published2008-09-16
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/34211
    titleMac OS X 10.5.x < 10.5.5 Multiple Vulnerabilities

Oval

accepted2013-07-29T04:00:24.200-04:00
classvulnerability
contributors
  • nameShane Shaffer
    organizationG2, Inc.
  • nameShane Shaffer
    organizationG2, Inc.
  • nameMaria Kedovskaya
    organizationALTX-SOFT
definition_extensions
commentApple QuickTime is installed
ovaloval:org.mitre.oval:def:12443
descriptionInteger overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, which triggers heap corruption.
familywindows
idoval:org.mitre.oval:def:15851
statusaccepted
submitted2012-12-11T16:37:33.623-05:00
titleInteger overflow in Apple QuickTime before 7.5.5 on Windows via a crafted PICT image, which triggers heap corruption
version7

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 31086 CVE ID:CVE-2008-3615 CVE-2008-3635 CVE-2008-3624 CVE-2008-3625 CVE-2008-3614 CVE-2008-3626 CVE-2008-3627 CVE-2008-3628 CVE-2008-3629 CNCVE ID:CNCVE-20083615 CNCVE-20083635 CNCVE-20083624 CNCVE-20083625 CNCVE-20083614 CNCVE-20083626 CNCVE-20083627 CNCVE-20083628 CNCVE-20083629 Apple QuickTime是一款苹果公司发布的媒体播放程序。 Apple QuickTime处理多种媒体文件多个安全问题,远程攻击者可以利用漏洞对应用程序进行拒绝服务或任意代码执行攻击。 CVE-2008-3627: Apple QuickTime处理AVC1 atoms存在整数溢出,可导致任意代码执行。 CVE-2008-3635: 利用Indeo video codec对QuickTime文件解析存在缺陷,QuickTimeInternetExtras.qtx中的不正确边界检查可导致基于堆栈的缓冲区溢出,可导致任意代码执行。 CVE-2008-3627: QuickTimeH264.scalar对mov视频文件存在缺陷,特殊构建的MDAT atom可导致堆破坏。 CVE-2008-3625: 处理全景跟踪PDAT atoms存在缺陷,当maxTilt, minFieldOfView和maxFieldOfView元素被破坏时,可导致基于栈的缓冲区溢出。 CVE-2008-3627: QuickTimeH264.qtx中的MP4视频文件处理存在缺陷,特殊构建的MDAT ATOM存在堆破坏漏洞。 CVE-2008-3626: CallComponentFunctionWithStorage()函数处理STSZ atoms存在缺陷,sample_size_table条目过大时可导致内存破坏。 CVE-2008-3624: 处理特殊构建的QTVR文件存在堆缓冲区溢出,可导致任意代码执行。 CVE-2008-3628: 处理特殊构建的PICT映像文件存在非法指针问题,可导致拒绝服务或者任意代码执行攻击。 Apple QuickTime Player 7.4.5 + Apple Mac OS X 10.4.9 + Apple Mac OS X 10.3.9 + Apple Mac OS X 10.5 + Apple Mac OS X Server 10.4.9 + Apple Mac OS X Server 10.3.9 + Apple Mac OS X Server 10.5 Apple QuickTime Player 7.4.1 Apple QuickTime Player 7.3.1 .70 Apple QuickTime Player 7.3.1 Apple QuickTime Player 7.1.6 Apple QuickTime Player 7.1.5 Apple QuickTime Player 7.1.4 Apple QuickTime Player 7.1.3 Apple QuickTime Player 7.1.2 Apple QuickTime Player 7.1.1 Apple QuickTime Player 7.0.4 Apple QuickTime Player 7.0.3 Apple QuickTime Player 7.0.2 Apple QuickTime Player 7.0.1 Apple QuickTime Player 7.0 Apple QuickTime Player 7.5 Apple QuickTime Player 7.4 Apple QuickTime Player 7.4 Apple QuickTime Player 7.3 Apple QuickTime Player 7.2 Apple QuickTime Player 7.1 升级到最新版本: Apple QuickTime Player 7.5 Apple iTunes8Setup.exe <a href=http://www.apple.com/quicktime/download/ target=_blank>http://www.apple.com/quicktime/download/</a> Apple QuickTime755_Leopard.dmg <a href=http://www.apple.com/quicktime/download/ target=_blank>http://www.apple.com/quicktime/download/</a> Apple QuickTime755_Tiger.dmg <a href=http://www.apple.com/quicktime/download/ target=_blank>http://www.apple.com/quicktime/download/</a> Apple QuickTimeInstaller.exe <a href=http://www.apple.com/quicktime/download/ target=_blank>http://www.apple.com/quicktime/download/</a>
idSSV:4026
last seen2017-11-19
modified2008-09-11
published2008-09-11
reporterRoot
titleApple QuickTime Movie/PICT/QTVR多个远程漏洞