CVE-2008-0234
published 2008-01-11CVE-2008-0234: Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute…
PriorityP350critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
12.40%
95.7th percentile
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | — | — |
| apple | quicktime | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
exploitdb·2008-01-14
CVE-2008-0234 QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
---
Quicktime Player 7.3.1.70 rtsp Remote Buffer Overflow Exploit PoC
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/4906.zip (2008-quicktimebof.zip)
# milw0rm.com [2008-01-14]
Exploit-DB
QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
exploitdb·2008-01-10
CVE-2008-0234 QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
---
#######################################################################
Luigi Auriemma
Application: Quicktime Player
http://www.apple.com/quicktime
Versions: <= 7.3.1.70
Platforms: Windows and Mac
Bug: buffer-overflow
Exploitation: remote
Date: 10 Jan 2008
Thanx to: swirl for the help during the re-testing of the bug
Author: Luigi Auriemma
e-mail: [email protected]
web: aluigi.org
#######################################################################
1) Introduction
2) Bug
3) The Code
4) Fix
#######################################################################
1) Introduction
Quicktime is a well known media player developed by Apple.
#######################################################################
2)
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2008/Feb/msg00001.htmlhttp://secunia.com/advisories/28423http://secunia.com/advisories/31034http://securityreason.com/securityalert/3537http://www.kb.cert.org/vuls/id/112179http://www.securityfocus.com/archive/1/486091/100/0/threadedhttp://www.securityfocus.com/archive/1/486114/100/0/threadedhttp://www.securityfocus.com/archive/1/486161/100/0/threadedhttp://www.securityfocus.com/archive/1/486174/100/0/threadedhttp://www.securityfocus.com/archive/1/486238/100/0/threadedhttp://www.securityfocus.com/archive/1/486241/100/0/threadedhttp://www.securityfocus.com/archive/1/486268/100/0/threadedhttp://www.securityfocus.com/bid/27225http://www.securitytracker.com/id?1019178http://www.vupen.com/english/advisories/2008/0107http://www.vupen.com/english/advisories/2008/2064/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39601https://www.exploit-db.com/exploits/4885https://www.exploit-db.com/exploits/4906http://lists.apple.com/archives/security-announce/2008//Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2008/Feb/msg00001.htmlhttp://secunia.com/advisories/28423http://secunia.com/advisories/31034http://securityreason.com/securityalert/3537http://www.kb.cert.org/vuls/id/112179http://www.securityfocus.com/archive/1/486091/100/0/threadedhttp://www.securityfocus.com/archive/1/486114/100/0/threadedhttp://www.securityfocus.com/archive/1/486161/100/0/threadedhttp://www.securityfocus.com/archive/1/486174/100/0/threadedhttp://www.securityfocus.com/archive/1/486238/100/0/threadedhttp://www.securityfocus.com/archive/1/486241/100/0/threadedhttp://www.securityfocus.com/archive/1/486268/100/0/threadedhttp://www.securityfocus.com/bid/27225http://www.securitytracker.com/id?1019178http://www.vupen.com/english/advisories/2008/0107http://www.vupen.com/english/advisories/2008/2064/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39601https://www.exploit-db.com/exploits/4885https://www.exploit-db.com/exploits/4906
2008-01-11
Published