Quantcast

New QuickTime Bug Exposes XP, Vista to Attack

Gregg Keizer, Computerworld

  • 0 Yes
  • 0 No

Security researchers warn that attack code targeting an unpatched bug in Apple Inc.'s QuickTime has gone public, and added that in-the-wild attacks against systems running Windows XP and Vista are probably not far behind.

There was no word as of Sunday whether the Mac OS X versions of the media player are also vulnerable.

The critical bug in QuickTime 7.2 and 7.3 (and perhaps earlier editions as well) is in the player's handling of the Real Time Streaming Protocol (RTSP), a audio/video streaming standard. According to alerts posted by Symantec Corp. and the U.S. Computer Emergency Readiness Team (US-CERT), attackers can exploit the flaw by duping users into visiting malicious or compromised Web sites hosting specially-crafted streaming content, or by convincing them to open a rigged QTL file attached to an e-mail message.

Symantec credited Polish research Krystian Kloskowski with first reporting the zero-day vulnerability on the milw0rm.com Web site Friday. By Saturday, Kloskowski and an unnamed researcher identified as "InTeL" had followed up with separate proof-of-concept examples that executed on Windows XP SP2 and Windows Vista machines running QuickTime 7.2 or 7.3.

A successful exploit would let the attacker install additional malware -- spyware or a spambot, say -- or cull the system for information like passwords. An attack that failed would likely only crash QuickTime.

A gaffe by Apple's developers, however, makes attack easier on Vista, said InTeL, who claimed that the QuickTimePlayer binary does not have Address Space Layout Randomization (ASLR) enabled. ASLR is a Vista security feature that randomly assigns data and application components, such as .exe and .dll files, to memory to make it tougher for attackers to determine the location of critical functions or vulnerable code.

Apple's forgetfulness prompted Symantec analyst Anthony Roe to note: "This makes reliable exploitation of the vulnerability a lot easier."

Another Symantec researcher, Patrick Jungles, added that QuickTime vulnerabilities usually draw attackers quickly. "In the past, we have seen a very short period of time between the release of proof-of-concept exploits for QuickTime vulnerabilities and the development of working exploits by attackers," said Jungles in a note to customers of his company's DeepSight threat network. "Popular applications such as QuickTime are strong candidates for exploitation in the wild."

Apple last patched QuickTime less than three weeks ago when it released version 7.3 to fix a number of critical image-rendering and Java-related vulnerabilities. So far in 2007, Apple has issued six QuickTime security-related updates that have fixed a total of 31 flaws.

Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.

  • Recommend this story?
  • 0 Yes
    0 No

"New QuickTime Bug Exposes XP, Vista to Attack" Comments

Related Software Articles

  • A Look at Sun's VirtualBox Virtualization continues to be a big topic among Mac users with Intel-powered Macs. Products from Parallels and VMware allow...
  • Bugs & Fixes: Fixing IPhone 2.0 Sync Problems It's been a tough week for Apple. First, there were the activation hassles during the iPhone 3G launch day. Next up were the...
  • How to Run X11 Apps on the Mac If you've ever thought about running Unix programs on your Mac, you might have assumed that meant you were stuck with the...
  • Bloomberg 1.1 for IPhone The App Store now lists 15 different applications in the News category, giving users a wide choice of products for their news...
  • Invoice 3 Adds Smart Coloring Kedisoft has announced Invoice 3, a new version of their invoice generation software for Mac OS X. It costs €79 (US$125.28).

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)