Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security VulnWatch
[Top] [All Lists]

[Full-disclosure] Fortinet Advisory: Apple Quick Time Player ImageWidth

Subject: [Full-disclosure] Fortinet Advisory: Apple Quick Time Player ImageWidth Denial of Service Vulnerability
Date: Thu, 12 Jan 2006 17:19:39 -0800 (PST)
Fortinet Security Advisory: FSA-2006-03

Apple QuickTime Player ImageWidth Denial of Service Vulnerability

Advisory Date      : January 12, 2006
Reported Date      : November 28, 2005
Vendor             : Apple computers
Affected Products  : Apple QuickTime Player v7.0.3
Severity           : Medium
Reference      : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3710
                 http://docs.info.apple.com/article.html?artnum=303101
                 http://www.securityfocus.com/bid/16202/info

Description        :  Fortinet Security Research Team (FSRT) has
discovered a Denial of Service Vulnerability in the Apple QuickTime
Player. Apple QuickTime has Denial of Service vulnerability in parsing the
specially crafted TIFF image files. This is due to application failure to
sanitize the parameter ImageWidth value while parsing TIFF image files. A
remote attacker could construct a web page with specially crafted tiff
file and entice a victim to view it, when the user opens the TIFF image
with Internet Explorer or Apple QuickTime Player, it'll cause memory
access violation, and leading to Denial of Service.

Impact             : Denial of Service

Solution           : Apple Computers has released a security update for
this vulnerability, which is available for downloading from Apples's web
site under security update.

Fortinet Protection: Fortinet is protecting network from this
vulnerability with latest IPS update.

Acknowledgment     : Dejun Meng of Fortinet Security Research team found
this vulnerability.

Disclaimer         : Although Fortinet has attempted to provide accurate
information in these materials, Fortinet assumes no legal responsibility
for the accuracy or completeness of the information. More specific
information is available on request from Fortinet. Please note that
Fortinet's product information does not constitute or contain any
guarantee, warranty or legally binding representation, unless expressly
identified as such in a duly signed writing.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>
  • [Full-disclosure] Fortinet Advisory: Apple Quick Time Player ImageWidth Denial of Service Vulnerability, Fortinet Research <=