Hi! This is the ezmlm program. I'm managing the
bugtraq@securityfocus.com mailing list.
I'm working for my owner, who can be reached
at bugtraq-owner@securityfocus.com.
Messages to you from the bugtraq mailing list seem to
have been bouncing. I've attached a copy of the first bounce
message I received.
If this message bounces too, I will send you a probe. If the probe bounces,
I will remove your address from the bugtraq mailing list,
without further notice.
I've kept a list of which messages from the bugtraq mailing list have
bounced from your address.
Copies of these messages may be in the archive.
To retrieve a set of messages 123-145 (a maximum of 100 per request),
send an empty message to:
<bugtraq-get.123_145@securityfocus.com>
To receive a subject and author list for the last 100 or so messages,
send an empty message to:
<bugtraq-index@securityfocus.com>
Here are the message numbers:
22800
22804
--- Enclosed is a copy of the bounce message I received.
Return-Path: <>
Received: (qmail 12833 invoked from network); 13 Jan 2006 23:13:23 -0000
Received: from outgoing.securityfocus.com (HELO outgoing3.securityfocus.com) (205.206.231.27)
by lists2.securityfocus.com with SMTP; 13 Jan 2006 23:13:23 -0000
Received: from mail.securityfocus.com (mail.securityfocus.com [205.206.231.9])
by outgoing3.securityfocus.com (Postfix) with SMTP id 9FFE2239075
for <bugtraq-return-22800-bugtraq=freebsd.csie.nctu.edu.tw@lists2.securityfo cus.com>; Fri, 13 Jan 2006 22:07:46 -0700 (MST)
Received: (qmail 2778 invoked by alias); 14 Jan 2006 05:35:49 -0000
Received: (qmail 887 invoked from network); 14 Jan 2006 05:35:23 -0000
Received: from outgoing.securityfocus.com (HELO outgoing3.securityfocus.com) (205.206.231.27)
by mail.securityfocus.com with SMTP; 14 Jan 2006 05:35:23 -0000
Received: by outgoing3.securityfocus.com (Postfix)
id DA996238C4F; Fri, 13 Jan 2006 22:07:05 -0700 (MST)
Date: Fri, 13 Jan 2006 22:07:05 -0700 (MST)
From: MAILER-DAEMON@securityfocus.com (Mail Delivery System)
Subject: Undelivered Mail Returned to Sender
To: bugtraq-return-22800-bugtraq=freebsd.csie.nctu.edu.tw@securityfocus.com
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status;
boundary="1D38A237D64.1137215185/outgoing3.securityfocus.com"
Message-Id: <20060114050705.DA996238C4F@outgoing3.securityfocu s.com>
This is a MIME-encapsulated message.
--1D38A237D64.1137215185/outgoing3.securityfocus.com
Content-Description: Notification
Content-Type: text/plain
This is the Postfix program at host outgoing3.securityfocus.com.
I'm sorry to have to inform you that your message could not be
be delivered to one or more recipients. It's attached below.
For further assistance, please send mail to <postmaster>
If you do so, please include this problem report. You can
delete your own text from the attached returned message.
The Postfix program
<bugtraq@freebsd.csie.nctu.edu.tw>: host
mgate1.csie.nctu.edu.tw[140.113.17.201] refused to talk to me: 421 4.4.1
cacy-fpe-srv-1.symantec.com Unable to contact destination
--1D38A237D64.1137215185/outgoing3.securityfocus.com
Content-Description: Delivery report
Content-Type: message/delivery-status
Reporting-MTA: dns; outgoing3.securityfocus.com
X-Postfix-Queue-ID: 1D38A237D64
X-Postfix-Sender: rfc822; bugtraq-return-22800@securityfocus.com
Arrival-Date: Wed, 11 Jan 2006 10:29:57 -0700 (MST)
Final-Recipient: rfc822; bugtraq@freebsd.csie.nctu.edu.tw
Action: failed
Status: 4.0.0
Diagnostic-Code: X-Postfix; host mgate1.csie.nctu.edu.tw[140.113.17.201]
refused to talk to me: 421 4.4.1 cacy-fpe-srv-1.symantec.com Unable to
contact destination
--1D38A237D64.1137215185/outgoing3.securityfocus.com
Content-Description: Undelivered Message
Content-Type: message/rfc822
Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20])
by outgoing3.securityfocus.com (Postfix) with QMQP
id 1D38A237D64; Wed, 11 Jan 2006 10:29:57 -0700 (MST)
Mailing-List: contact bugtraq-help@securityfocus.com; run by ezmlm
Precedence: bulk
List-Id: <bugtraq.list-id.securityfocus.com>
List-Post: <mailto:bugtraq@securityfocus.com>
List-Help: <mailto:bugtraq-help@securityfocus.com>
List-Unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
List-Subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
Delivered-To: mailing list bugtraq@securityfocus.com
Delivered-To: moderator for bugtraq@securityfocus.com
Received: (qmail 8972 invoked from network); 11 Jan 2006 11:02:34 -0000
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Subject: [EEYEB-20051117B] Apple iTunes (QuickTime.qts) Heap Overflow
X-MimeOLE: Produced By Microsoft Exchange V6.5
Date: Wed, 11 Jan 2006 09:35:16 -0800
Message-ID: <D52FCFAE57472647956CBAEDC08DA5537344D6@av-mail01.corp.int-eeye.com>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: [EEYEB-20051117B] Apple iTunes (QuickTime.qts) Heap Overflow
Thread-Index: AcYW1WJ71FrXsXDIRem2Xwzjowo90g==
From: "Advisories" <Advisories@eeye.com>
To: <full-disclosure@lists.grok.org.uk>, <ntbugtraq@ntbugtraq.com>,
<bugtraq@securityfocus.com>, <vulnwatch@vulnwatch.org>
X-OriginalArrivalTime: 11 Jan 2006 17:35:17.0822 (UTC) FILETIME=[6367A5E0:01C616D5]
EEYEB-20051117B Apple iTunes (QuickTime.qts) Heap Overflow
Release Date:
January 10, 2006
Date Reported:
November 17, 2005
Patch Development Time (In Days):
54 Days
Severity:
High (Code Execution)
Vendor:
Apple
Systems Affected:
Quicktime on Windows 2000
Quicktime on Windows XP
Quicktime on Mac OS X 10.3.9
Apple iTunes on Windows 2000
Apple iTunes on Windows XP
Apple iTunes on OS X 10.3.9
Overview:
eEye Digital Security has discovered a critical vulnerability in Apple
iTunes. The vulnerability allows an attacker to reliably overwrite heap
memory with user-controlled data and execute arbitrary code in the
context of the user who executed iTunes.
This specific flaw exists within the QuickTime.qts file which many
applications access QuickTime's functionality through. By specially
crafting atoms within a movie file, a direct heap overwrite is
triggered, and reliable code execution is then possible.
Technical Details:
The code in QuickTime.qts responsible for copying Movie Resource atom
type sizes in a QuickTime-format movie into an array allocated on the
heap. According to developer.apple.com, the format of the Movie Resource
atom is as follows:
Field Description
---------------------------
Atom Size 4 bytes
Atom Type 4 bytes
Data Variable
By supplying the .MOV file with a large atom size results in a
insufficiently-sized heap block to be allocated, resulting in a complete
heap memory overwrite ultimately failing in the List_Component()
function. =20
References
QuickTime: QuickTime File Format
http://developer.apple.com/documenta...TFF/index.html
Vendor Status:
Apple has released a patch for this vulnerability. The patch is
available via the Updates section of the affected applications.
This vulnerability has been assigned the CVE identifier CAN-2004-0431.
Credit:
Discovery: Karl Lynn
Copyright (c) 1998-2006 eEye Digital Security
Permission is hereby granted for the redistribution of this alert
electronically. It is not to be edited in any way without express
consent of eEye. If you wish to reprint the whole or any part of this
alert in any other medium excluding electronic medium, please email
alert@eEye.com for permission.
Disclaimer
The information within this paper may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There
are no warranties, implied or express, with regard to this information.
In no event shall the author be liable for any direct or indirect
damages whatsoever arising out of or in connection with the use or
spread of this information. Any use of this information is at the user's
own risk.
--1D38A237D64.1137215185/outgoing3.securityfocus.com--

Likes:

Quote