[NT] QuickTime PictureViewer GIF Images DoS Vulnerability (Depth)

SecuriTeam <[email protected]>
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  QuickTime PictureViewer GIF Images DoS Vulnerability (Depth)
------------------------------------------------------------------------


SUMMARY

 <http://www.apple.com/quicktime/player/> QuickTime Player is "a media 
player produced by Apple. QuickTime  player contains a module 
PictureViewer to view still images". PictureViewer for Windows suffers 
from a vulnerability that allows an attacker to crash the program when 
opening a specially crafted GIF file.

DETAILS

Vulnerable Systems:
 * QuickTime Player for Windows version 6.5.2

PictureViewer does not check for correct value in the depth start field of 
the GIF header. In the test.gif provided below this value is set to 255 
(0xff hexadecimal). When setting depth start to value between 0x00 and 
0xfe PictureViewer reports that file is corrupted. It leads to assumption 
that there is some kind of integer overflow in processing GIF files. Also, 
changing the  width and height of logical screen in GIF header will also 
provide similar results.

Exploit Code:
And here is test.gif:
00000000 :47 49 46 38 39 61 0F 01 - 0F 01 00 00 00 21 F9 04
00000010 :00 00 00 00 00 2C 00 00 - 00 00 00 01 00 01 00 FF

To exploit, open a hex editor and create a new file with the contents 
above, or modify an existing GIF file header.


ADDITIONAL INFORMATION

The information has been provided by  <mailto:[email protected]> 
liquid.



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.