ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit

QuickTime flaw reported

Ina Fried CNET News.com

Published: 09 Nov 2005 09:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Less than three weeks after Apple issued an update to patch four security flaws in its QuickTime media player, a new "critical" problem has been discovered.

The unpatched vulnerability could allow remote execution of code, according to an advisory published on Monday by eEye Digital Security. It affects various versions of Apple QuickTime running on all types of operating systems, the company said, but did not specify which versions in particular were at risk.

eEye said it notified Apple of the flaw on 31 October, when it outlined vulnerabilities that were not addressed in Apple's update of 12 October. And although Apple issued a security advisory on 3 November regarding its patch and the four flaws, that advisory did not address the new flaw eEye discovered, said Mike Puterbaugh, eEye's senior product marketing director.

"We don't feel this flaw could result in an Internet worm, as it does require end-user interaction (such as clicking on a link to a malicious Web site or chat session). The affected component is, however, enabled by default," Puterbaugh said.

This newly discovered flaw could allow an attacker to pose as the logged-in user and launch remotely executable code. An intruder, for example, could access and do everything that a user could do on his computer. If the user had administrator rights, the hacker could also access everything that the administrator could.

"The Apple flaw works with their latest version of QuickTime," said Steve Manzuik, eEye product manager. "The only similarity with the earlier flaws is it's in QuickTime."

The new issue affects a different QuickTime function than the four earlier flaws, which included a missing movie attribute that could be interpreted as an extension. The absence of the actual extension is not detected, resulting in a "dereference of a null pointer".

Another of the earlier four flaws included an integer overflow that could be remotely exploited through a specially crafted video file.

eEye has declined to provide more specifics in its security advisories until the vendor has issued a patch. That policy is designed to prevent hackers from reverse engineering the problem to launch an attack while the vendor works to fix the flaw.

Apple's earlier patch, version 7.0.3, addressed vulnerabilities found in QuickTime 6.5.2 and 7.0.1 for the Mac OS X operating system and some versions running on Windows. One of those flaws allowed a malicious attacker to launch a denial-of-service attack, while the other three flaws allowed an attacker to remotely execute code and take over users' computers.

Apple told ZDNet UK sister site CNET News.com that it was not prepared to comment at this time. Manzuik said that on Monday Apple acknowledged receipt of eEye's advisory, but gave no indication of when, or if, it plans to patch the flaw.

"It is something they will undoubtedly have to patch," he added.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
68 out of 143 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Logical Data Modeller / Data Architect - Contract

Logical Data Modeller / Data Architect required for 6 month contract with strong extension prospects based in the south west. The position offers ...

Project Manager for Utilities Company - West Midlands - 3 mths

Project Manager needed to work a 3-month contract with likely extension for a major West Midlands Utilities provider. You will be familiar with all ...

ASP.NET Developer

My client is looking for a web developer on a 6-month contractor with possible extension options and competitive rates. They are located in ...

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.

Featured Talkback

if the OLPC winds up as a vehicle to create a dependence on Windows for millions of poor people, the net effect for humanity will be negative. What makes it good is if it leads the users to freedom through free, freedom-respecting software.

By: mattlee

Read full story:
Negroponte: Windows key to OLPC philosophy