« Newer Technology to Debut MaxPower Wireless Networking Line at Macworld | Home | Macworld - Moscone PacMan »
January 11, 2008
Researchers Discover Buffer Overflow Vulnerability in QuickTime 7.3.1
The good news: QuickTime is an effective media unit for the Mac OS X and Windows operating systems that handles a wide variety of formats and makes playback quick and easy.
The bad news: Sometimes they find a security hole in it that makes you wonder why you bought a computer in the first place.
According to MacNN, Italian researcher Luigi Auriemma has stated that the has discovered a buffer overflow problem in QuickTime 7.3.1 allowing malicious code to be executed. The problem apparently surfaces when QuickTime attempts to launch a Real Time Streaming Protocol link and port 554 is closed. The software will then attempt to access port 80 and trigger an error message that causes the buffer overflow.
Apparently both the Windows and Mac OS X version of QuickTime are affected and the existence of the bug has been confirmed by Alfred Huger, vice president of development at Symantec Security Response. Huger, who observed the proof-of-concept code for the bug, stated that he only managed to crash Quicktime, but, "it's a safe assumption that if you can do that you may be able to execute remote code," he says. "It's very serious."
Huger comments that despite a seeming increase in attacks on Apple platforms, hackers do not care about Apple specifically. Instead, Huger says, they are interested in any widely-available platform, which maximizes distribution.
Stay tuned for more information on this as it becomes available and if you've seen a similar instance of this, let us know in the comments or forums.
Posted by chrisbarylick at January 11, 2008 2:15 PM
Category: Security
Buy from: Apple, iTunes
, Amazon
.
Digg This |
Post to del.icio.us |
Post to Furl
- Apple Offers Complimentary Repairs for Select MacBook Pro Notebooks with Nvidia Chips
- Apple Patent Suggests Possible Voice Commands for iPhone, iPod Touch and/or Apple TV
- Delicious Library Updated to 2.0.4
- Apple Releases Security Update 2008-007
- Adium X Reaches 1.3.2
- Apple to Hold Notebook Event on October 14th
- AT&T Launches Online Account Setup For iPhone 3G Customers
- Apple Announces iPhone Tech Talk World Tour
- Potential Next-Gen MacBook Shots Leaked, Lower Price Point Mentioned
- Opinion: Trying to Do the Right Thing
- Upcoming RealVNC Version to Add iPhone, Additional Handset Support
- Opera 9.60 Out the Door
- Shaker Pulled From App Store
- Blackberry Storm Enters Touch-Screen Device Fray (Updated)
- VLC Updated to 0.9.4
Trackback Pings
TrackBack URL for this entry:
http://www.powerpage.org/mt/mt-tb.cgi/10855










