Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:STC:DL:QT-FPX-IO

Severity

Major

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Apple QuickTime FPX File Integer Overflow

Release Date

2010/10/04

Update Number

1784

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Apple QuickTime FPX File Integer Overflow


This signature detects attempts to exploit a known vulnerability in QuickTime FPX file parser. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.

Extended Description

Two vulnerabilities have been reported in Apple QuickTime and iTunes: - an integer overflow - a heap-based buffer overflow These issues affect both Mac OS X and Microsoft Windows releases of the software. A successful exploit will result in the execution of arbitrary code in the context of the currently logged-in user.

Affected Products

  • Apple itunes 6.0.1
  • Apple itunes 6.0.2
  • Apple mac_os_x 10.3.9
  • Apple mac_os_x 10.4.0
  • Apple mac_os_x 10.4.1
  • Apple mac_os_x 10.4.2
  • Apple mac_os_x 10.4.3
  • Apple mac_os_x 10.4.4
  • Apple mac_os_x 10.4.5
  • Apple mac_os_x 10.4.6
  • Apple mac_os_x_server 10.3.9
  • Apple mac_os_x_server 10.4.0
  • Apple mac_os_x_server 10.4.1
  • Apple mac_os_x_server 10.4.2
  • Apple mac_os_x_server 10.4.3
  • Apple mac_os_x_server 10.4.4
  • Apple mac_os_x_server 10.4.5
  • Apple mac_os_x_server 10.4.6
  • Apple quicktime_player 7.0.3
  • Apple quicktime_player 7.0.4

References

  • BugTraq: 17074
  • CVE: CVE-2006-1249

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out