Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > January 2009 > 3751 - APPLE-SA-2009-01-21 QuickTime MPEG-2 Playback Component

January 2009

3751 - APPLE-SA-2009-01-21 QuickTime MPEG-2 Playback Component

ID: 3751
Date: 22/01/2009

Title: 3751 - APPLE-SA-2009-01-21 QuickTime MPEG-2 Playback Component
Platform level affected:Operating System
Hardware components affected:Intel PC
Specific operating systems components affected: 32-bit Windows
Net-enabled software: Other
Security software:Other
Other software: Other
Remediation Summary:Update your copy of the software with the download available from the supplier.
Vendors affected:Apple
Applications affected:QuickTime MPEG-2 Playback Component
Adversity source: Unknown
Attack Vector: Vulnerability exploitation
Virulence: Unknown
Warning Status: Active
Potential Damage: Remote execution/modification
Possible Duration: Open Ended
Availability of fix: Available
Type of fix: Patch
Source: www.apple.com
Reliability of source: Trusted
Source URL: http://www.apple.com/quicktime/mpeg2/
CVE: CVE-2009-0008
Abstract: The QuickTime MPEG-2 Playback Component for Windows is now available and addresses an input validation issue that exists in the QuickTime MPEG-2 Playback Component for Windows.

APPLE-SA-2009-01-21 QuickTime MPEG-2 Playback Component

The QuickTime MPEG-2 Playback Component for Windows is now available and addresses the following issue:

CVE-ID:  CVE-2009-0008

Available for:  Windows Vista, XP SP2 and SP3

Impact:  Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution

Description:  An input validation issue exists in the QuickTime
MPEG-2 Playback Component for Windows. Accessing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of MPEG-2 files. This issue does not affect systems running Mac OS X. Credit to Richard Lemon of Code Lemon for reporting this issue.

The QuickTime MPEG-2 Playback Component is not installed by default, and is provided separately from QuickTime. Details are available via http://www.apple.com/quicktime/mpeg2/ Users who have paid for and downloaded an earlier version of the QuickTime MPEG-2 Playback Component from the Apple Store may download the updated version for free.

The steps to determine that a system has the updated version are listed at http://support.apple.com/kb/HT3381.
The version number of the updated QuickTime MPEG-2 Playback Component for Windows is 7.60.92.0.

Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222

This message is signed with Apple's Product Security PGP key, and details are available at:
http://www.apple.com/support/security/pgp/

This advisory contains information released by the original author. Some of the information may have changed since it was released. If the issue affects you, it may be prudent to retrieve the advisory from the site of the original source to ensure that you receive the most current information concerning that problem. Reference to any specific commercial product, process, or service by trade name, trademark manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favouring by CPNI.

The views and opinions of authors expressed within this notice shall not be used for advertising or product endorsement purposes. CPNI shall not accept responsibility for any errors or omissions contained within this advisory. In particular, they shall not be liable for any loss or damage whatsoever, arising from or in connection with the usage of information contained within this advisory.

CSIRTUK is a member of the Forum of Incident Response and Security Teams (FIRST) and has contacts with other international Incident Response Teams (IRTs) in order to foster cooperation and coordination in incident prevention, to prompt rapid reaction to incidents, and to promote information sharing amongst its members and the community at large.

Thu, 22 Jan 2009 09:30:00 GMT
Domain affected: Technical
  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |