Apple QuickTime < 7.7.8 Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 9305

Synopsis

The version of QuickTime on the remote machine is affected by multiple code execution vulnerabilities.

Description

Versions of QuickTime older than 7.7.8 are affected by the following vulnerabilities :

- A flaw is triggered as user-supplied input is not properly validated when handling URL atom sizes. With a specially crafted file, a context-dependent attacker can corrupt memory and potentially execute arbitrary code. (CVE-2015-3788)
- A flaw is triggered as user-supplied input is not properly validated when handling 3GPP STSD sample description entry sizes. With a specially crafted file, a context-dependent attacker can corrupt memory and potentially execute arbitrary code. (CVE-2015-3789)
- A flaw is triggered as user-supplied input is not properly validated when handling MVHD atom sizes. With a specially crafted file, a context-dependent attacker can corrupt memory and potentially execute arbitrary code. (CVE-2015-3790)
- A flaw is triggered as user-supplied input is not properly validated when handling mismatching ESDS atom descriptor type lengths. With a specially crafted file, a context-dependent attacker can corrupt memory and potentially execute arbitrary code. (CVE-2015-3791)
- A flaw is triggered as user-supplied input is not properly validated when handling MDAT sections. With a specially crafted file, a context-dependent attacker can corrupt memory and potentially execute arbitrary code. (CVE-2015-3792)
- A flaw is triggered as user-supplied input is not properly validated. With a specially crafted file, a context-dependent attacker can corrupt memory and potentially execute arbitrary code. (CVE-2015-5751, CVE-2015-5779, CVE-2015-5785, CVE-2015-5786)

Solution

Upgrade to QuickTime 7.7.8 or later.

See Also

https://support.apple.com/en-us/HT205046

Plugin Details

Severity: High

ID: 9305

Family: Web Clients

Published: 2016/04/20

Modified: 2018/09/16

Dependencies: 1735, 8314

Nessus ID: 85662

Risk Information

Risk Factor: High

CVSSv2

Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

CVSSv3

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apple:quicktime

Patch Publication Date: 2015/08/13

Vulnerability Publication Date: 2015/08/13

Reference Information

CVE: CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5779, CVE-2015-5785, CVE-2015-5786

BID: 76340, 76443, 76444

IAVB: 2015-B-0105