CVE-2008-0234
Apple Quicktime < 7.4.1 - Remote Code Execution via RTSP Reason-Phrase Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-0234. PoCs published by Luigi Auriemma.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Quicktime Player 7.3.1.70 via RTSP, allowing remote code execution. The PoC is hosted as a binary exploit in a ZIP file, typical for older exploits.
Description
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.
Exploits (2)
This exploit targets a buffer overflow vulnerability in Quicktime Player 7.3.1.70 via RTSP, allowing remote code execution. The PoC is hosted as a binary exploit in a ZIP file, typical for older exploits.
This exploit demonstrates a buffer overflow vulnerability in QuickTime Player <= 7.3.1.70. The PoC triggers the overflow by sending a malformed HTTP 404 response to an RTSP request, which overwrites the return address in the LCD-like status screen.