On TechRepublic: Why Android beats iPhone
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Nov 4, 2005 5:17:00 PM

Apple Computer late Thursday issued an alert about flaws in its QuickTime media player that could allow a malicious attacker to launch a denial-of-service attack or remote code execution.

QuickTime versions 6.5.2 and 7.0.1 for the Mac OS X operating system are affected by the vulnerabilities, as well as some versions for Microsoft Windows, according to a Friday report by security company Secunia, which rated the vulnerabilities "highly critical."

Apple has issued an update, QuickTime 7.0.3, to fix the four flaws. The patch was posted to Apple's Web site on Oct. 12.

One vulnerability can result in a denial-of-service, or DOS, attack against any application loading remotely originated content. The flaw involves a missing movie attribute, which is interpreted as an extension. The absence of the actual extension, however, is not detected, resulting in a "dereference of a null pointer," Apple warned.

Another security hole involves an integer overflow that may be remotely exploited through a specially crafted video file. This could lead to an arbitrary execution of code.

"Three of the vulnerabilities can launch malicious code that allows an attacker to snoop on users," said Thomas Kristensen, Secunia's chief technology officer. "The other vulnerability is a DOS attack that will only work in a few cases and crash the media player when it tries to open a file."

Last June, Apple released QuickTime 7.0.1 to address a security flaw and deliver several improvements to its media player. The update was designed to modify the Quartz Composer plug-in, which previously could allow an attacker to tap into local data and distribute it to an arbitrary Web site.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 42 Talkback(s)
Actually when hey patch the core OS ...
... it is a 3rd party patch since the core is BSD with a proprietary GUI. (Read the rest)
Posted by: ShadeTree Posted on: 11/07/05 You are currently: a Guest | | Terms of Use
Gee, imagine that!  Confused by religion | 11/04/05
Actually  mabricen | 11/04/05
Try this...  vdraken | 11/04/05
Think you missed the sarcasm... (NT)  3D0G | 11/04/05
Probably.  vdraken | 11/04/05
It comes up daily  Boot_Agnostic | 11/05/05
Apple sounds alarm over QuickTime flaws  Loverock Davidson | 11/04/05
just a ie  mabricen | 11/04/05
To make MS look better?  Rick_K | 11/04/05
dur...  Elekt | 11/04/05
Actually it's not.  Rick_K | 11/04/05
well then...  Elekt | 11/04/05
It's how the OS is...  Rick_K | 11/04/05
Amen  Richard Flude | 11/04/05
Too bad  Loverock Davidson | 11/04/05
Not a flamebait.  Rick_K | 11/04/05
An old issue  Ken_z | 11/04/05
So it seems...  Qbt | 11/04/05
Well not yet  DebianDog | 11/04/05
Not quite...  Qbt | 11/04/05
Man  baggins_z | 11/04/05
No,  Qbt | 11/04/05
'bout time  Elekt | 11/04/05
Must be some form of evny.  Rick_K | 11/04/05
Try this...  Elekt | 11/04/05
You missed the point.  Rick_K | 11/04/05
RE: You Missed The Point  Elekt | 11/04/05
Only when  Rick_K | 11/04/05
But Steve is very convincing!  tic swayback | 11/04/05
Address his facts.  vdraken | 11/04/05
LOL  Rick_K | 11/04/05
??  Elekt | 11/04/05
Quite simple  Rick_K | 11/04/05
No  Real World | 11/05/05
Actually when hey patch the core OS ...  ShadeTree | 11/07/05
Better Headline  baggins_z | 11/04/05
Wrong  Qbt | 11/04/05
Still don't get it....  Laff | 11/05/05
QuickTime for Windows...  Anton Philidor | 11/04/05
Don't you get it Zdnet,  Boot_Agnostic | 11/06/05
Don't understand your point?  Laff | 11/06/05
Just, if it isn't a MS patch to ridicule them for  Boot_Agnostic | 11/07/05

What do you think?

advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here