Quantcast

New QuickTime Flaw Found

Jim Dalrymple, IDG News Service

  • 0 Yes
  • 0 No

The United States Computer Emergency Readiness Team (US-CERT) has discovered a new buffer overflow vulnerability with Apple's QuickTime media software.

The vulnerability affects both Mac and Windows operating systems. Because QuickTime is part of Apple's popular iTunes jukebox software, that application is also affected, researchers said.

The vulnerability is found in the way QuickTime handles RTSP response messages. When attempting to display a specially crafted Reason-Phrase, QuickTime Player crashes at a memory location that can be controlled by an attacker, according to US-CERT.

The organization also said that they are aware of publicly available proof-of-concept code for this vulnerability.

US-CERT offers several solutions to the problem including uninstalling QuickTime, Blocking the RTSP protocol and disabling the QuickTime plug-ins in your Web browser.

Attackers targeted QuickTime in December in a separate RTSP vulnerability that Apple later fixed with a software update.

Apple representatives were not immediately available for comment.

Macworld
For more Macintosh computing news, visit Macworld. Story copyright © 2007 Mac Publishing LLC. All rights reserved.

  • Recommend this story?
  • 0 Yes
    0 No

"New QuickTime Flaw Found" Comments

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

People who read this also read:

  • 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
  • Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.

PC World's Marketplace