Symantec Warns About New QuickTime Bug

By Max Brenn
21:17, November 26th 2007
79 votes
Vote this story
Symantec Warns About New QuickTime Bug

In a security alert published on its website, Symantec disclosed today that Apple QuickTime contains a remote buffer overflow vulnerability that could be exploited by the hackers.

Symantec rated the vulnerability as “high”. “Apple QuickTime is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized stack-based memory buffer. This issue occurs when handling specially crafted RTSP Response headers. Attackers can leverage this issue to execute arbitrary machine code in the context of the user running the affected application,” said Symantec in its alert.

According to the security company successful exploits of the vulnerability will compromise the application and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.

Symantec discovered that QuickTime 7.2 and 7.3 are vulnerable to this issue, but the security experts warned that other versions may also be affected.

U.S. Computer Emergency Readiness Team confirmed the flaw and they suggested a few workarounds: block the rtsp:// protocol, disable the QuickTime ActiveX controls in Internet Explorer and QuickTime plug-ins in Mozilla based browsers or disable file association for QuickTime files.

As QuickTimes is part Apple’s iTunes, the installations of this program are also affected by this vulnerability, noted US-CERT.

The last update of QuickTime, 7.3, was released by Apple at the beginning of this month.



© 2007 - 2009 - eFluxMedia
dotclear

Other News in

Cisco Releases Home Audio System

  Cisco Systems has decided, as it has stated, to conquer the consumer market as well as it has the professional crowd. Until now, save for the odd attempt at social networking, nothing...

Jobs-less Macworld, Disappointing

Jobs-less Macworld, Disappointing

You can never say that Macworld is boring – but it can disappoint you. Such was the case of the last Macworld, which has been criticized by tech reviewers for the lack of novelty and low...

Asus’ S121 Notebook Fitted with SSD, Windows 7

Asus’ S121 Notebook Fitted with SSD, Windows 7

On Tuesday, Asustek Computer Incorporated introduced an ultrathin, light netbook called the S121, which is fitted with both the yet to be released Microsoft’s Windows 7 operating system and the...

CES To Open, But Nothing Spectacular Announced

CES To Open, But Nothing Spectacular Announced

This year's Consumer Electronics Show (CES), the biggest tech industry event of 2009, will probably show evolutionary products, but that are unlikely to shake-up the market. The devices will...

Portland Gives Up Its Wires For Clearwire’s 4G WiMAX Coverage

Portland Gives Up Its Wires For Clearwire’s 4G WiMAX Coverage

Portland gave up its wires this week, when Clearwire launched the first 4G WiMAX wireless broadband network in the West, and one of the few in the country (together with those in Baltimore and...

dotclear
Latest videos in Technology
Gadget Show Goes on Despite...
Apple Announces ITunes Price...
Macworld Goes on Without...
Apple CEO says healthy to lead
IIHS: Small Cars Making...

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Wikipedia Raised $6.2 Million from DonationsWikipedia Raised $6.2 Million from Donations

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
Lower Revenue For IntelLower Revenue For Intel

» read full story
dotclear