Latest Comments
"trend is good antivirus software."
by jack | Dec 3, 2008 7:02 AM
 
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM

QuickTime exploit disclosed for 1-week-old version

  • Email a Friend
  • Print Page
By Dan Kaplan
Sep 19, 2008 9:52 AM
Tags: QuickTime | exploit | disclosed | for | 1-week-old | version
It didn't take long for an exploit to emerge in Apple QuickTime version 7.5.5.

On Monday, one week after Apple pushed out a security update for the popular media-playing program, resulting in 7.5.5, a fresh exploit was posted to the Milw0rm website.

According to Symantec's DeepSight service, the exploit can create a denial-of-service condition due to an error in the processing of the '<?quicktime type=?>' parameter when handling long strings.

The exploit also can crash iTunes or any program that uses a QuickTime plug-in, Mac security firm Intego said Thursday in a memo.

Based on the existing exploit code, the company rated the risk 'low'.

But Intego said the files containing the strings could handle an additional payload that would allow for the execution of arbitrary code 'with no user interaction, other than an attempt to view a file'.

In lieu of a fix, customers are encouraged to safely browse the web, DeepSight analyst Aaron Adams said in a journal entry. He recommended disabling third-party plug-ins and to run the browser with the least privileges possible.

An Apple spokeswoman did not immediately respond to a request for comment on Thursday.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers