| Apple QuickTime RTSP buffer overflow |
|
|
| Sistemas Operativos Implicados: | Windows XP/NT/2K/Me/98/95 |
| Aplicações Implicadas: | Indefinido |
Overview
Apple QuickTime contains a stack buffer overflow vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service condition.I. Description
Real Time Streaming Protocol (RTSP) is a protocol that is used by streaming media systems. The Apple QuickTime Streaming Server and QuickTime player both support for RTSP.Apple QuickTime contains a stack buffer overflow vulnerability in the way QuickTime handles the RTSP Content-Type header. This vulnerability may be exploited by convincing a user to connect to a specially crafted RTSP stream. Note that QuickTime is a component of Apple iTunes, therefore iTunes installations are also affected by this vulnerability. We are aware of publicly available exploit code for this vulnerability. II. Impact III. Solution
Limited testing has shown that QuickTime versions 4.0 through 7.3 are vulnerable on all supported Mac and Windows platforms.
Block the rtsp:// protocol
Blocking the RTSP protocol with proxy or firewall rules may help mitigate this vulnerability. Note that RTSP (default 554/tcp and 6970-6999/udp) may use a variety of port numbers, so blocking the protocol based on a particular port may not be sufficient.
Disable the QuickTime ActiveX controls in Internet Explorer
The QuickTime ActiveX controls can be disabled in Internet Explorer by setting the kill bit for the following CLSIDs:
Systems Affected
| Vendor | Status | Date Updated |
|---|---|---|
| Apple Computer, Inc. | Vulnerable | 25-Nov-2007 |
References
http://www.cert.org/tech_tips/securing_browser/ Credit
http://www.beskerming.com/security/2007/11/25/74/QuickTime_-_Remote_hacker_automatic_control
http://www.milw0rm.com/exploits/4648
http://tools.ietf.org/html/rfc2326
http://tools.ietf.org/html/rfc2326#section-12.16
http://www.apple.com/quicktime/technologies/streaming/
http://www.gnucitizen.org/blog/backdooring-mp3-files/
http://developer.apple.com/quicktime/icefloe/dispatch028.html
http://www.apple.com/quicktime/resources/qt/us/proxy/
This vulnerability was publicly disclosed by Krystian Kloskowski.
This document was written by Ryan Giobbi and Will Dormann.
O CERT.PT tem como missão contribuir para o esforço de cibersegurança nacional nomeadamente no tratamento e coordenação da resposta a incidentes, na produção de alertas e recomendações de segurança e na promoção de uma cultura de segurança em Portugal.
Av. do Brasil 101
1700-066 Lisboa
Portugal
Tel: +351 218440177 (9h30-12h30, 14h00-17h30; GMT)
Fax: +351 218472167
email:
pgp: 342A 17BA DF71 E193 6871 0357 8BDE A247 C523 AAE7