ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Apple QuickTime zero-day flaw 'extremely critical'

Tom Espiner ZDNet.co.uk

Published: 26 Nov 2007 12:46 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security research firm Secunia has reported what it calls an "extremely critical" vulnerability in media-streaming program Apple QuickTime.

The flaw, which affects the latest versions of QuickTime, 7.x, has not been patched and could allow a hacker to gain remote control of an affected system. It lies in a boundary error, when the program processes Real Time Streaming Protocol (RTSP) replies, according to Secunia's advisory, published on Monday. RTSP allows a client to remotely control video streams.

Working exploit code is in the wild, said Secunia, which linked from its advisory to details of the code on another security research site, milw0rm, which is where the vulnerability was initially recorded by Polish security researcher Krystian Kloskowski.

According to Kloskowski, exploit code can be executed on Windows Vista operating systems and systems running Microsoft XP Service Pack 2.

Secunia is advising that users do not browse untrusted websites, follow untrusted links, or open untrusted QuickTime Media Link files.

Elia Florio, a security researcher for Symantec, wrote on Symantec's Security Response Weblog that some QuickTime browser plug-ins appear to prevent any shell code being executed.

With Internet Explorer versions 6 and 7, and the Safari 3 beta, the attack appears to be prevented because standard buffer overflow prevention processes act before any damage can be done, Florio wrote. With Firefox, the QuickTime RTSP response is unmoderated. As a result, the exploit works against Firefox if QuickTime is the default multimedia player, according to Florio.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
21 out of 21 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

GBS-0088233 CRM Infrastructure Architect

Your responsibilities will include: - Working with IBM Strategy Consultants and Application Architects and our clients to explore optimal platforms ...

Role: Java, an interest in Eclipse (plug ins) worked with EJBs

Role: Java, an interest in Eclipse (plug ins) worked with EJBs My exclusive client based in Wiltshire are looking for a new member of their team to ...

Associate Director of Business Intelligence

You will represent the Trust on local, regional and national professional forums and will ensure that the Trust is well positioned to exploit any ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment