On CBSSports.com: Now Mickelson's mother has breast cancer
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jan 23, 2007 10:40:00 PM

Apple on Tuesday released a fix for a serious security hole in its QuickTime media player software.

The patch comes 23 days after details of the flaw, along with detailed attack code, were publicly released. The publication kicked off the "Month of the Apple Bugs" project, which has been publishing a new Apple software bug each day in January.

The QuickTime vulnerability relates to how the media player software handles the Real Time Streaming Protocol, or RTSP, according to an Apple alert. An attacker could exploit the flaw and commandeer a vulnerable system by placing a special RTSP string in a QuickTime file and tricking a user into opening that file, Apple said.

"A buffer overflow exists in QuickTime's handling of RTSP URLs," according to the Apple alert. "By enticing a user to access a maliciously-crafted RTSP URL, an attacker can trigger the buffer overflow, which may lead to arbitrary code execution." The update addresses the issue by performing additional validation of RTSP links, Apple said.

Security-monitoring companies Secunia and the French Security Incidence Response Team, or FrSIRT, have rated the QuickTime problem as "highly critical" and "critical," respectively. Still, experts have not seen widespread exploitation of the problem.

One of the bug hunters behind the Month of Apple Bugs said he is stunned by the time it took Apple to fix the flaw. "Twenty two days for a remote issue that leads to code execution right away is sort of insane," the pseudonymous LMH said in an interview via instant message. "There was already an exploit and it was being abused in targeted attacks."

The vulnerability affects QuickTime 7.1.3 on Mac OS X and Windows. Several other vulnerabilities in Apple software have been disclosed as part of the Month of Apple Bugs, including in QuickTime. Apple has not yet released fixes for those issues.

Apple has said that it is aware of the project, but has chosen not to comment beyond a standard statement that it takes security very seriously and has "a great track record of addressing potential vulnerabilities before they can affect users. We always welcome feedback on how to improve security on the Mac."

The Apple patch can be downloaded and installed via the Software Update feature in Mac OS X, or from Apple Downloads.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 30 Talkback(s)
I've had no problems with Windows or Linux either
your level of satisfaction seems to be in the extreme minority.

Everyone I know can say the same about Windows too. No problems and certainly so scrambling to install things like ... (Read the rest)
Posted by: NonZealot Posted on: 01/25/07 You are currently: a Guest | | Terms of Use
It was fast  greenwizard88 | 01/23/07
It was fast enough  999ad@... | 01/23/07
As long as  mdemuth | 01/23/07
Sure anything within "30" days is reasonable too me.  Laff | 01/24/07
"23" days is the perfect amount  NonZealot | 01/24/07
Man you AppleZealots are too much....:P  Laff | 01/24/07
I don't think  Shelendrea | 01/24/07
Oh I realize he was NOT being an AppleZealot....  Laff | 01/24/07
Took longer than I would have said for Apple  Boot_Agnostic | 01/23/07
Apple's security "alert" document is a joke.  PB_z | 01/23/07
Did you even read it?  Rick_K | 01/24/07
But I thought Macs were flawless?  NonZealot | 01/23/07
Message has been deleted.  whisperycat | 01/24/07
It's a common and understandable misconception:P  Laff | 01/24/07
Yes, I'd love to use an OS like OSX  NonZealot | 01/24/07
MORTAL!!! Do not doubt the Apple!!!!  Laff | 01/24/07
Keep on posting, buddy  Tigertank | 01/24/07
Please don't reply to my posts any more  NonZealot | 01/24/07
raving lunatic... and i'm serious.. that's my conclusion.  doctorSpoc | 01/24/07
Apple stocker?  NonZealot | 01/24/07
please do us and yourself a favour and get back on your meds nt.  doctorSpoc | 01/24/07
Dispute....who cares!?!  Laff | 01/24/07
Pay attention!  frabjous | 01/24/07
It's true...  Rick_K | 01/24/07
No, there are not  Boot_Agnostic | 01/24/07
Very Amusing  Shelendrea | 01/24/07
22, 23 days?  joe6pack_z | 01/24/07
Well...  nomorems | 01/24/07
Really?  frabjous | 01/24/07
I've had no problems with Windows or Linux either  NonZealot | 01/25/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

advertisement
Click Here