Apple Released Details on Four QuickTime Security Vulnerabilities Fixed in v7.0.3
CVE-ID: CVE-2005-2753--An integer overflow may be exploitable
via remotely originated content
Description: A sign extension of an embedded "Pascal" style string
could result in a very large memory copy. The update treats the
string as having unsigned length. Credit to Piotr Bania
(bania.piotr@gmail.com) for reporting this issue.CVE-ID: CVE-2005-2754--An integer overflow may be exploitable
via remotely originated content
Description: Improper movie attributes could result in a very large
memory copy. The update checks for a valid non-zero size before
copying. Credit to Piotr Bania (bania.piotr@gmail.com) for reporting
this issue.CVE-ID: CVE-2005-2755--A denial of service against any application
loading remotely-originated content
Description: A missing movie attribute is interpreted as an
extension, but the absence of the extension is not flagged as an
error, resulting in a de-reference of a NULL pointer. The update
requires either the movie attribute or the extension to be present
for a well-formed movie. Credit to Piotr Bania
(bania.piotr@gmail.com) for reporting this issue.CVE-ID: CVE-2005-2756--Compressed PICT data may overwrite application memory
from remotely originated content
Description: Expansion of compressed PICT data could exceed the size
of the destination buffer. The update prevents decompressed data
from exceeding the destination buffer size. Credit to Piotr Bania
(bania.piotr@gmail.com) for reporting this issue.
[Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?