Apple Released Details on Four QuickTime Security Vulnerabilities Fixed in v7.0.3

We reported that Apple released QuickTime v7.0.3 on October 12 but Apple just released the details of the security enhancements included for Mac OS X 10.3.9 and later plus Windows 2000/XP in QuickTime 7.0.3. They are:

CVE-ID: CVE-2005-2753--An integer overflow may be exploitable
via remotely originated content
Description: A sign extension of an embedded "Pascal" style string
could result in a very large memory copy. The update treats the
string as having unsigned length. Credit to Piotr Bania
(bania.piotr@gmail.com) for reporting this issue.

CVE-ID: CVE-2005-2754--An integer overflow may be exploitable
via remotely originated content
Description: Improper movie attributes could result in a very large
memory copy. The update checks for a valid non-zero size before
copying. Credit to Piotr Bania (bania.piotr@gmail.com) for reporting
this issue.

CVE-ID: CVE-2005-2755--A denial of service against any application
loading remotely-originated content
Description: A missing movie attribute is interpreted as an
extension, but the absence of the extension is not flagged as an
error, resulting in a de-reference of a NULL pointer. The update
requires either the movie attribute or the extension to be present
for a well-formed movie. Credit to Piotr Bania
(bania.piotr@gmail.com) for reporting this issue.

CVE-ID: CVE-2005-2756--Compressed PICT data may overwrite application memory
from remotely originated content
Description: Expansion of compressed PICT data could exceed the size
of the destination buffer. The update prevents decompressed data
from exceeding the destination buffer size. Credit to Piotr Bania
(bania.piotr@gmail.com) for reporting this issue.

[Bill Fox]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Mac OS · This month in the archive