Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Apple QuickTime Streaming Debug Error Logging Buffer Overflow Vulnerability

Subscribe

Check Point Reference: CPAI-2010-256
Date Published:
Severity:
Last Updated:
Source: Secunia Advisory: SA40729
Industry Reference(s): CVE-2010-1799
Protection Provided by: Security Gateway
  • R71
  • R70
IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Apple Quicktime 7.6.6 and prior
Vulnerability Description
A stack buffer overflow vulnerability has been reported in Apple QuickTime. Apple QuickTime is a media player application that is capable of playing back numerous multimedia file formats from local file system or network servers. A remote attacker could exploit this issue via a malformed SMIL file. Successful exploitation of this vulnerability may allow execution of arbitrary code on a target system.
Vulnerability Details
The vulnerability is due to a boundary error in the QuickTimeStreaming.qtx file while writing a debug log error. A remote attacker could exploit this
issue by enticing target users to open a crafted SMIL file containing an overly long URL. Successful exploitation would cause the application to terminate abnormally, and  and may allow execution of arbitrary code on the vulnerable system.

Protection Overview
This protection will detect and block attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05Protection taband select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway: R70/R71

How Can I Protect My Network?
1. In the IPS tab, click Protections > By Protocol > Application Intelligence > Content Protection.
2. In the right pane, double-click the Apple QuickTime Streaming Debug Error Logging Buffer Overflow protection.
3. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect), and apply Additional Settings
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries: 

Attack Name: Content Protection Violation
Attack Information: Apple QuickTime streaming debug error logging buffer overflow

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > Badfiles, and select the SMIL Parser protection group.
3. Click Apple QuickTime Streaming Debug Error Logging Buffer Overflow (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: Badfiles SMIL Parser
Description: Apple QuickTime Streaming Debug Error Logging Buffer Overflow