[NT] QuickTime PictureViewer GIF Images DoS Vulnerability (Depth)
SecuriTeam <[email protected]>
| Newsgroups | gmane.comp.security.securiteam |
|---|---|
| Message-ID | <[email protected]> |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - QuickTime PictureViewer GIF Images DoS Vulnerability (Depth) ------------------------------------------------------------------------ SUMMARY <http://www.apple.com/quicktime/player/> QuickTime Player is "a media player produced by Apple. QuickTime player contains a module PictureViewer to view still images". PictureViewer for Windows suffers from a vulnerability that allows an attacker to crash the program when opening a specially crafted GIF file. DETAILS Vulnerable Systems: * QuickTime Player for Windows version 6.5.2 PictureViewer does not check for correct value in the depth start field of the GIF header. In the test.gif provided below this value is set to 255 (0xff hexadecimal). When setting depth start to value between 0x00 and 0xfe PictureViewer reports that file is corrupted. It leads to assumption that there is some kind of integer overflow in processing GIF files. Also, changing the width and height of logical screen in GIF header will also provide similar results. Exploit Code: And here is test.gif: 00000000 :47 49 46 38 39 61 0F 01 - 0F 01 00 00 00 21 F9 04 00000010 :00 00 00 00 00 2C 00 00 - 00 00 00 01 00 01 00 FF To exploit, open a hex editor and create a new file with the contents above, or modify an existing GIF file header. ADDITIONAL INFORMATION The information has been provided by <mailto:[email protected]> liquid. ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] In order to subscribe to the mailing list, simply forward this email to: [email protected] ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.