[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Apple QuickTime Targa image Buffer Overflow

Author
Senator of Pirates
Risk
[
Security Risk High
]
0day-ID
0day-ID-19805
Category
dos / poc
Date add
26-11-2012
Platform
windows
Application : Apple QuickTime
Versions : <=  before 7.7.3
CVE : 2012-3755
Impact : 9.3 (High)
References :
http://lists.apple.com/archives/security-announce/2012/Nov/msg00002.html
Auther : Senator of Pirates
E-Mail : SenatorofPirates.team[at]gmail.com
FaceBook : /SenatorofPirates
                    /SenatorofPiratesInfo

Vulnerability :
 
A buffer overflow vulnerability in QuickTime PictureViewer.exe and the
specific flaw exists within TGA file images encoded data, When encountering
an invalid encoded width field and can be result a heap-based buffer
overflow occur.
And this vulnerability allows remote attackers to execute arbitrary code or
cause a denial of service (application crash) via a crafted Targa image. 

PoC :
 
http://www18.zippyshare.com/v/40547915/file.html

#  0day.today [2024-11-14]  #