Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

18443

July 26th, 2010 16:00

Now PATCHED: QuickTime Player Streaming Debug Error Logging Buffer Overflow

The following has been copied/pasted from http://secunia.com/advisories/40729/

Description
Krystian Kloskowski has discovered a [highly critical] vulnerability in QuickTime Player, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error in QuickTimeStreaming.qtx when constructing a string to write to a debug log file. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into viewing a specially crafted web page that references a SMIL file containing an overly long URL.

Successful exploitation allows execution of arbitrary code.

The vulnerability is confirmed in version 7.6.6 (1671) for Windows. Other versions may also be affected.

[NO] Solution
A patch or updated version is not currently available.

EDIT:   By virtue of this QuickTime vulnerability, Secunia is now reporting all my browswers (IE, FF, Opera) as being insecure.

 

No Responses!
No Events found!

Top