CVE-2013-1017
published 2013-05-24CVE-2013-1017: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted…
PriorityP357critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
32.55%
98.1th percentile
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie file.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | <= 7.7.3 | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted .mov files containing a 'rdrf' or 'dref' atom with a zero-length size field (\x00\x00\x00\x00) followed by an 'alis' data reference type, which is the trigger condition for the buffer overflow. ↗
- →Monitor for QuickTime browser plugin (NPSWF or QuickTime ActiveX) loading .mov files served with Content-Type 'application/octet-stream' from a web server, which is the delivery mechanism used by the Metasploit module. ↗
- →Post-exploitation: watch for a process migration event immediately after QuickTime plugin execution (InitialAutoRunScript 'migrate -f'), indicating shellcode has run and migrated out of the browser process. ↗
- →ROP gadget addresses from Quicktime.qts can be used as memory indicators: 0x66923467 (QT 7.7.3), 0x669211C7 (QT 7.7.2), 0x66920D67 (QT 7.7.1), 0x66920BD7 (QT 7.7.0) — presence of these addresses in memory or crash dumps indicates exploitation of this specific module. ↗
- ·The Metasploit module targets only Windows XP SP3 with IE 8 across QuickTime versions 7.7.0–7.7.3; ROP gadget addresses are version-specific to Quicktime.qts and will not work on other OS/browser combinations without retargeting. ↗
- ·The ROP chain relies on msvcrt.dll gadgets at hardcoded addresses (e.g., 0x77c1e844, 0x77c4fa1c); these are ASLR-disabled addresses specific to Windows XP SP3 msvcrt.dll and will differ on other Windows versions. ↗
- ·Null bytes are bad characters for the payload delivery mechanism (js_property_spray); payloads containing \x00 will be corrupted. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
exploitdb·2013-08-29·CVSS 9.0
CVE-2013-4982 [CRITICAL] AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
---
Core Security - Corelabs Advisory
http://corelabs.coresecurity.com/
AVTECH DVR multiple vulnerabilities
1. *Advisory Information*
Title: AVTECH DVR multiple vulnerabilities
Advisory ID: CORE-2013-0726
Advisory URL:
http://www.coresecurity.com/advisories/avtech-dvr-multiple-vulnerabilities
Date published: 2013-08-28
Date of last update: 2013-08-28
Vendors contacted: AVTECH Corporation
Release mode: User release
2. *Vulnerability Information*
Class: Buffer overflow [CWE-119], Buffer overflow [CWE-119], Improper
Access Control [CWE-284]
Impact: Code execution, Security bypass
Remotely Exploitable: Yes
Locally Exploitable: No
CVE Name: CVE-2013-4980, CVE-2013-4981, CVE-2013-4982
3. *Vulnerability Description*
Mu
Exploit-DB
Apple QuickTime 7 - Invalid Atom Length Buffer Overflow (Metasploit)
exploitdb·2013-07-22
CVE-2013-1017 Apple QuickTime 7 - Invalid Atom Length Buffer Overflow (Metasploit)
Apple QuickTime 7 - Invalid Atom Length Buffer Overflow (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit4 "Apple Quicktime 7 Invalid Atom Length Buffer Overflow",
'Description' => %q{
This module exploits a vulnerability found in Apple Quicktime. The flaw is
triggered when Quicktime fails to properly handle the data length for certain
atoms such as 'rdrf' or 'dref' in the Alis record, which may result a buffer
overflow by loading a specially crafted .mov file, and allows arbitrary
code execution under the context of the user.
},
'
Metasploit
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
metasploit
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
This module exploits a vulnerability found in Apple Quicktime. The flaw is triggered when Quicktime fails to properly handle the data length for certain atoms such as 'rdrf' or 'dref' in the Alis record, which may result a buffer overflow by loading a specially crafted .mov file, and allows arbitrary code execution under the context of the current user.
Metasploit
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
metasploit
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
This module exploits a vulnerability found in Apple QuickTime. The flaw is triggered when QuickTime fails to properly handle the data length for certain atoms such as 'rdrf' or 'dref' in the Alis record, which may result a buffer overflow by loading a specially crafted .mov file, and allows arbitrary code execution under the context of the current user. Please note: Since an egghunter is used to search for the payload, this may require additional time for the exploit to complete.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2013/May/msg00001.htmlhttp://support.apple.com/kb/HT5770https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16606http://lists.apple.com/archives/security-announce/2013/May/msg00001.htmlhttp://support.apple.com/kb/HT5770https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16606
2013-05-24
Published