ID

VAR-200905-0043


CVE

CVE-2009-0010


TITLE

Apple Mac OS X of QuickDraw Manager and Apple QuickTime Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2009-001331

DESCRIPTION

Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a crafted 0x77 Poly tag and a crafted length field, which triggers a heap-based buffer overflow. While processing data for opcode 0x71 QuickTime trusts a value contained in the file and makes an allocation accordingly. By providing a malicious value this buffer can be undersized and subsequently can be overflowed leading to arbitrary code execution under the context of the user running QuickTime. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists when the application parses a malformed .PICT image. While decoding a tag 0x77 in the image, the application misuses a 16-bit length when allocating tag data. When copying tag data into this buffer, a heap overflow occurs. This can lead to code execution under the context of the current user. The QuickDraw component of Apple Mac OS X is prone to a memory-corruption vulnerability. An attacker can exploit this issue by tricking a victim into opening a specially crafted PICT image file. A successful exploit will allow arbitrary attacker-supplied code to run in the context of the victim running the affected application. NOTE: This issue was previously covered in BID 34926 (Apple Mac OS X 2009-002 Multiple Security Vulnerabilities), but has been assigned its own record to better document it. The way PICT graphics are handled has an integer underflow that can lead to a heap overflow, and opening a malicious PICT graphic could lead to unexpected application termination or arbitrary code execution. ZDI-09-021: Apple QuickTime PICT Unspecified Tag Heap Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-021 May 13, 2009 -- CVE ID: CVE-2009-0010 -- Affected Vendors: Apple -- Affected Products: Apple Quicktime -- TippingPoint(TM) IPS Customer Protection: TippingPoint IPS customers have been protected against this vulnerability by Digital Vaccine protection filter ID 8048. -- Vendor Response: Apple has issued an update to correct this vulnerability. More details can be found at: http://support.apple.com/kb/HT3549 -- Disclosure Timeline: 2009-04-15 - Vulnerability reported to vendor 2009-05-13 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * Damian Put, Sebastian Apelt -- About the Zero Day Initiative (ZDI): Established by TippingPoint, The Zero Day Initiative (ZDI) represents a best-of-breed model for rewarding security researchers for responsibly disclosing discovered vulnerabilities. Researchers interested in getting paid for their security research through the ZDI can find more information and sign-up at: http://www.zerodayinitiative.com The ZDI is unique in how the acquired vulnerability information is used. TippingPoint does not re-sell the vulnerability details or any exploit code. Instead, upon notifying the affected product vendor, TippingPoint provides its customers with zero day protection through its intrusion prevention technology. Explicit details regarding the specifics of the vulnerability are not exposed to any parties until an official vendor patch is publicly available. Furthermore, with the altruistic aim of helping to secure a broader user base, TippingPoint provides this vulnerability information confidentially to security vendors (including competitors) who have a vulnerability protection or mitigation product. Our vulnerability disclosure policy is available online at: http://www.zerodayinitiative.com/advisories/disclosure_policy/

Trust: 3.69

sources: NVD: CVE-2009-0010 // JVNDB: JVNDB-2009-001331 // ZDI: ZDI-09-030 // ZDI: ZDI-09-021 // BID: 34937 // BID: 34938 // VULHUB: VHN-37456 // PACKETSTORM: 77915 // PACKETSTORM: 78025

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:eqversion:10.4.11

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.5.6

Trust: 1.6

vendor:applemodel:quicktimescope: - version: -

Trust: 1.4

vendor:applemodel:mac os xscope:eqversion:10.5.2

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.5.3

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.5.5

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.5

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.5.4

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.5.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.5.1

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:v10.4.11

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:v10.5 to v10.5.6

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:v10.4.11

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:v10.5 to v10.5.6

Trust: 0.8

vendor:applemodel:quicktimescope:ltversion:7.6.2

Trust: 0.8

vendor:applemodel:mac os serverscope:eqversion:x10.5.6

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.5.5

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.5.4

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.5.3

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.5.2

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.5.1

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.11

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.10

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.9

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.8

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.7

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.6

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.5

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.4

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.3

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.2

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4.1

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.4

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.5

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.5.6

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.5.5

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.5.4

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.5.3

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.5.2

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.5.1

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.11

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.10

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.9

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.8

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.7

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.6

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.5

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.4

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.3

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.2

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4.1

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.4

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.5

Trust: 0.6

vendor:applemodel:mac os serverscope:neversion:x10.5.7

Trust: 0.6

vendor:applemodel:mac osscope:neversion:x10.5.7

Trust: 0.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.6

Trust: 0.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.2

Trust: 0.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.1

Trust: 0.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.4

Trust: 0.6

vendor:applemodel:mac os x serverscope:eqversion:10.5

Trust: 0.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.0

Trust: 0.6

vendor:applemodel:mac os x serverscope:eqversion:10.4.11

Trust: 0.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.3

Trust: 0.6

vendor:applemodel:quicktime playerscope:eqversion:7.0.3

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.5

Trust: 0.3

vendor:applemodel:quicktime playerscope:neversion:7.6.2

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.4

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.2

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.4.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.5

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.2

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.3.1.70

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.4

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.3

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.6

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.3.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.3

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0.4

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.5.5

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.6

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.4.5

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.6.1

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0.2

Trust: 0.3

vendor:applemodel:quicktime playerscope:eqversion:7.0.1

Trust: 0.3

sources: ZDI: ZDI-09-030 // ZDI: ZDI-09-021 // BID: 34937 // BID: 34938 // JVNDB: JVNDB-2009-001331 // CNNVD: CNNVD-200905-163 // NVD: CVE-2009-0010

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-0010
value: HIGH

Trust: 1.0

NVD: CVE-2009-0010
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200905-163
value: CRITICAL

Trust: 0.6

VULHUB: VHN-37456
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2009-0010
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-37456
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-37456 // JVNDB: JVNDB-2009-001331 // CNNVD: CNNVD-200905-163 // NVD: CVE-2009-0010

PROBLEMTYPE DATA

problemtype:CWE-189

Trust: 1.9

sources: VULHUB: VHN-37456 // JVNDB: JVNDB-2009-001331 // NVD: CVE-2009-0010

THREAT TYPE

remote

Trust: 0.8

sources: PACKETSTORM: 77915 // PACKETSTORM: 78025 // CNNVD: CNNVD-200905-163

TYPE

digital error

Trust: 0.6

sources: CNNVD: CNNVD-200905-163

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-001331

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-37456

PATCH

title:HT3591url:http://support.apple.com/kb/HT3591

Trust: 1.5

title:HT3549url:http://support.apple.com/kb/HT3549

Trust: 1.5

title:HT3591url:http://support.apple.com/kb/HT3591?viewlocale=ja_JP

Trust: 0.8

title:HT3549url:http://support.apple.com/kb/HT3549?viewlocale=ja_JP

Trust: 0.8

title:TA09-133Aurl:http://software.fujitsu.com/jp/security/vulnerabilities/ta09-133a.html

Trust: 0.8

sources: ZDI: ZDI-09-030 // ZDI: ZDI-09-021 // JVNDB: JVNDB-2009-001331

EXTERNAL IDS

db:NVDid:CVE-2009-0010

Trust: 4.7

db:ZDIid:ZDI-09-021

Trust: 2.8

db:BIDid:34938

Trust: 2.8

db:SECUNIAid:35074

Trust: 2.5

db:SECUNIAid:35091

Trust: 2.5

db:VUPENid:ADV-2009-1297

Trust: 2.5

db:VUPENid:ADV-2009-1407

Trust: 2.5

db:USCERTid:TA09-133A

Trust: 2.5

db:SECTRACKid:1022209

Trust: 2.5

db:BIDid:34926

Trust: 1.7

db:ZDIid:ZDI-09-030

Trust: 1.1

db:USCERTid:SA09-133A

Trust: 0.8

db:JVNDBid:JVNDB-2009-001331

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-413

Trust: 0.7

db:ZDI_CANid:ZDI-CAN-470

Trust: 0.7

db:CNNVDid:CNNVD-200905-163

Trust: 0.7

db:APPLEid:APPLE-SA-2009-05-12

Trust: 0.6

db:APPLEid:APPLE-SA-2009-06-01-1

Trust: 0.6

db:BUGTRAQid:20090527 ZDI-09-021: APPLE QUICKTIME PICT UNSPECIFIED TAG HEAP OVERFLOW VULNERABILITY

Trust: 0.6

db:CERT/CCid:TA09-133A

Trust: 0.6

db:BIDid:34937

Trust: 0.3

db:PACKETSTORMid:78025

Trust: 0.2

db:PACKETSTORMid:77915

Trust: 0.2

db:VULHUBid:VHN-37456

Trust: 0.1

sources: ZDI: ZDI-09-030 // ZDI: ZDI-09-021 // VULHUB: VHN-37456 // BID: 34937 // BID: 34938 // JVNDB: JVNDB-2009-001331 // PACKETSTORM: 77915 // PACKETSTORM: 78025 // CNNVD: CNNVD-200905-163 // NVD: CVE-2009-0010

REFERENCES

url:http://support.apple.com/kb/ht3591

Trust: 2.5

url:http://support.apple.com/kb/ht3549

Trust: 2.5

url:http://www.securityfocus.com/bid/34938

Trust: 2.5

url:http://www.us-cert.gov/cas/techalerts/ta09-133a.html

Trust: 2.5

url:http://www.securitytracker.com/id?1022209

Trust: 2.5

url:http://secunia.com/advisories/35074

Trust: 2.5

url:http://secunia.com/advisories/35091

Trust: 2.5

url:http://www.vupen.com/english/advisories/2009/1297

Trust: 2.5

url:http://www.vupen.com/english/advisories/2009/1407

Trust: 2.5

url:http://www.zerodayinitiative.com/advisories/zdi-09-021/

Trust: 2.0

url:http://www.zerodayinitiative.com/advisories/zdi-09-021

Trust: 1.8

url:http://lists.apple.com/archives/security-announce/2009/may/msg00002.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2009/jun/msg00000.html

Trust: 1.7

url:http://www.securityfocus.com/bid/34926

Trust: 1.7

url:http://www.vupen.com/exploits/apple_quicktime_pict_poly_tag_parsing_heap_overflow_poc_exploit_1407144.php

Trust: 1.7

url:http://www.securityfocus.com/archive/1/503878/100/0/threaded

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-0010

Trust: 0.8

url:http://jvn.jp/cert/jvnta09-133a/

Trust: 0.8

url:http://jvn.jp/tr/jvntr-2009-12

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-0010

Trust: 0.8

url:http://www.us-cert.gov/cas/alerts/sa09-133a.html

Trust: 0.8

url:http://www.apple.com/macosx/

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/503878/100/0/threaded

Trust: 0.6

url:/archive/1/503878

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-09-030/

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/disclosure_policy/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2009-0010

Trust: 0.2

url:http://www.tippingpoint.com

Trust: 0.2

url:http://www.zerodayinitiative.com

Trust: 0.2

url:http://www.zerodayinitiative.com/advisories/zdi-09-030

Trust: 0.1

sources: ZDI: ZDI-09-030 // ZDI: ZDI-09-021 // VULHUB: VHN-37456 // BID: 34937 // BID: 34938 // JVNDB: JVNDB-2009-001331 // PACKETSTORM: 77915 // PACKETSTORM: 78025 // CNNVD: CNNVD-200905-163 // NVD: CVE-2009-0010

CREDITS

Sebastian Apelt (sebastian.apelt@siberas.de)

Trust: 0.7

sources: ZDI: ZDI-09-030

SOURCES

db:ZDIid:ZDI-09-030
db:ZDIid:ZDI-09-021
db:VULHUBid:VHN-37456
db:BIDid:34937
db:BIDid:34938
db:JVNDBid:JVNDB-2009-001331
db:PACKETSTORMid:77915
db:PACKETSTORMid:78025
db:CNNVDid:CNNVD-200905-163
db:NVDid:CVE-2009-0010

LAST UPDATE DATE

2024-11-22T21:20:27.877000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-09-030date:2009-06-02T00:00:00
db:ZDIid:ZDI-09-021date:2009-05-13T00:00:00
db:VULHUBid:VHN-37456date:2018-10-11T00:00:00
db:BIDid:34937date:2015-05-07T18:19:00
db:BIDid:34938date:2009-06-11T22:09:00
db:JVNDBid:JVNDB-2009-001331date:2009-06-29T00:00:00
db:CNNVDid:CNNVD-200905-163date:2009-06-04T00:00:00
db:NVDid:CVE-2009-0010date:2018-10-11T20:58:40.320

SOURCES RELEASE DATE

db:ZDIid:ZDI-09-030date:2009-06-02T00:00:00
db:ZDIid:ZDI-09-021date:2009-05-13T00:00:00
db:VULHUBid:VHN-37456date:2009-05-13T00:00:00
db:BIDid:34937date:2009-05-12T00:00:00
db:BIDid:34938date:2009-05-12T00:00:00
db:JVNDBid:JVNDB-2009-001331date:2009-06-29T00:00:00
db:PACKETSTORMid:77915date:2009-05-29T00:23:10
db:PACKETSTORMid:78025date:2009-06-03T03:52:59
db:CNNVDid:CNNVD-200905-163date:2009-02-13T00:00:00
db:NVDid:CVE-2009-0010date:2009-05-13T15:30:00.233