This post is more than 5 years old
3 Apprentice
•
15.5K Posts
0
18443
July 26th, 2010 16:00
Now PATCHED: QuickTime Player Streaming Debug Error Logging Buffer Overflow
The following has been copied/pasted from http://secunia.com/advisories/40729/
Description
Krystian Kloskowski has discovered a [highly critical] vulnerability in QuickTime Player, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error in QuickTimeStreaming.qtx when constructing a string to write to a debug log file. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into viewing a specially crafted web page that references a SMIL file containing an overly long URL.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in version 7.6.6 (1671) for Windows. Other versions may also be affected.
[NO] Solution
A patch or updated version is not currently available.
EDIT: By virtue of this QuickTime vulnerability, Secunia is now reporting all my browswers (IE, FF, Opera) as being insecure.