Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-29-2007, 10:20 PM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 295
Zero-Day Exploit for Apple QuickTime Vulnerability

Zero-Day Exploit for Apple QuickTime Vulnerability
<p>Proof of concept exploit code for a newly discovered vulnerability in Apple's QuickTime player has been made available to the public today. The vulnerability (<a href="http://www.securityfocus.com/bid/26560">Apple QuickTime RTSP Response Header Content-Length Remote Buffer Overflow Vulnerability</a>) was first reported on November 23rd by Polish security researcher Krystian Kloskowski. </p>

<p>The publicly released exploit works successfully when tested with the latest stand-alone QuickTime player application version 7.3. It does not seem to execute any shellcode when tested with the QuickTime browser plugin even though the browser crashes due to the buffer overflow.</p>

<p>At the moment we believe the most likely attack scenarios to appear using this vulnerability could be:<br />
1. Email based attacks.<br />
2. Web browser based attacks.</p>

<p>In the email attack scenario the user receives a malicious email with an attachment containing a file with some extension associated by default to QuickTime Player (e.g. .mov, .qt, qtl., gsm, .3gp, etc). The attachment is not actually a media file, but instead it is an XML file which will force the player to open an RTSP connection on port 554 to the malicious server hosting the exploit. When the QuickTime Player contacts the remote server, it receives back the malformed RTSP response which triggers the buffer overflow and the execution of the attacker’s shellcode immediately. This attack requires users to double-click on the QuickTime multimedia attachment to run. It is worth bearing in mind that this attack may also work with other common media formats such as mpeg, .avi, and other MIME types that are associated with the QuickTime player.</p>

<p>In the Web browser attack scenario, the attack will most likely start with a hyperlinked URL sent to the user. When the user clicks on the URL, the browser loads a page that has a QuickTime streaming object embedded in it. The object initiates the RTSP connection to the malicious server on port 554 and exploit code is sent in response.</p>

<p>We have tested the exploit behavior of the current exploit against some of the common Web browsers. We have seen that with Internet Explorer 6/7 and Safari 3 Beta the attack is prevented. </p>

<p><a href="http://www.symantec.com/enterprise/security_response/weblog/upload/2007/11/Image_IE.html" onclick="window.open('http://www.symantec.com/enterprise/security_response/weblog/upload/2007/11/Image_IE.html','popup','width=552,height=588,scrol lbars=no,resizable=no,toolbar=no,directories=no,lo cation=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="View Image" src="http://www.symantec.com/enterprise/security_response/weblog/upload/2007/11/Image_IE.jpg" width="370"/></a></p>

<p>The browser in this case loads the QuickTime Player as an internal plugin and when the overflow occurs, it triggers some standard buffer overflow protection that shut downs the affected processes before any damage can be done. Attackers may attempt to refine the exploit in the coming days in order to overcome this initial hiccup and work to create a reliable exploit that works on Internet Explorer.</p>

<p>Firefox users are more susceptible to this attack because Firefox farms off the request directly to the QuickTime Player as a separate process outside of its control. As a result, the current version of the exploit works perfectly against Firefox if users have chosen QuickTime as the default player for multimedia formats. </p>

<p><a href="http://www.symantec.com/enterprise/security_response/weblog/upload/2007/11/Image_FF.html" onclick="window.open('http://www.symantec.com/enterprise/security_response/weblog/upload/2007/11/Image_FF.html','popup','width=589,height=620,scrol lbars=no,resizable=no,toolbar=no,directories=no,lo cation=no,menubar=no,status=no,left=0,top=0'); return false"><img alt="View Image" src="http://www.symantec.com/enterprise/security_response/weblog/upload/2007/11/Image_FF.jpg" width="370" /></a></p>

<p>At this time there is no patch available to resolve this issue so to reduce the risk against this threat users are advised to restrict out bound connections on TCP 554 using their firewalls and to avoid following links to untrusted Web sites. </p>
http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html
http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html
Sun, 25 Nov 2007 10:45:00 -0800
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 01:55 PM.


    Firefox 2