Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:DL:QT-PV-OF

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Apple QuickTime PictureViewer Buffer Overflow

Release Date

2011/12/21

Update Number

2052

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Apple QuickTime PictureViewer Buffer Overflow


A vulnerability exists in the PictureViewer component of the Apple QuickTime products. The affected product does not correctly process JPEG image files, allowing for a buffer overflow condition to be triggered by a malicious JPEG image. This flaw may allow an attacker to exploit the vulnerable product in order to create a denial of service condition or execute arbitrary code on the vulnerable system. In a simple attack case, the affected application will terminate upon opening of the malicious JPEG image file. In a more sophisticated attack scenario, where code injection and execution is attempted, the behaviour of the target is dependent on the intention of the injected code.

Extended Description

Apple QuickTime is reportedly prone to a buffer overflow when viewing malformed image files. This issue was reported to exist in QuickTime 6.5.1 for Windows. Other versions may also be affected. This issue may be related to BID 11553.

Affected Products

  • Apple QuickTime Player 6.5.1

References

  • BugTraq: 12905
  • CVE: CVE-2005-0903

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out