PDA

View Full Version : Quicktime/ITunes vulnerability


Needa Pass Rush
01-14-2008, 02:17 PM
My IT guy is suggesting uninstalling these applications until there is a fix. Google (news) Quicktime for more info. Thank you Apple!

New QuickTime Flaw Found
Both Windows and Mac versions of the multimedia program have a buffer overflow flaw that puts users at risk.
Jim Dalrymple, IDG News Service
Saturday, January 12, 2008 06:30 AM PST
The United States Computer Emergency Readiness Team (US-CERT) has discovered a new buffer overflow vulnerability with Apple's QuickTime media software.

The vulnerability affects both Mac and Windows operating systems. Because QuickTime is part of Apple's popular iTunes jukebox software, that application is also affected, researchers said.

The vulnerability is found in the way QuickTime handles RTSP response messages. When attempting to display a specially crafted Reason-Phrase, QuickTime Player crashes at a memory location that can be controlled by an attacker, according to US-CERT.

The organization also said that they are aware of publicly available proof-of-concept code for this vulnerability.

US-CERT offers several solutions to the problem including uninstalling QuickTime, Blocking the RTSP protocol and disabling the QuickTime plug-ins in your Web browser.

Attackers targeted QuickTime in December in a separate RTSP vulnerability that Apple later fixed with a software update.

Apple representatives were not immediately available for comment.

Los Broncos
01-14-2008, 02:21 PM
Your IT guy is pretty smart, they both suck till fixed.

Dead Head
01-14-2008, 02:23 PM
Hmmm...Not really concerned.

Chris
01-14-2008, 02:25 PM
< anti-apple.

broncosteven
01-14-2008, 04:24 PM
< anti-apple.

Nope, Apple has flaws all the time. I post some here and there from CERT to remind people nothing a human makes is perfect.

Beantown Bronco
01-14-2008, 04:38 PM
to remind people nothing a human makes is perfect.

Apparently, my parents aren't human. I knew it!

Kaylore
01-14-2008, 04:47 PM
What? But apple users have assured me that Apple computers are completely immune to viruses of any kind! This is a lie! :poke:

Chris
01-14-2008, 04:57 PM
Confused Steve. Just saying I don't care for Apple. Cultish marketing annoys me.

Dead Head
01-14-2008, 05:29 PM
What? But apple users have assured me that Apple computers are completely immune to viruses of any kind! This is a lie! :poke:

It's not a lie. These people actually believe it to be true. The belief is out of ignorance, but still.

Bronx33
01-14-2008, 05:51 PM
Attackers targeted QuickTime in December in a separate RTSP vulnerability that Apple later fixed with a software update.


People really need to find better hobbies this kinda crap needs a 100 lashes with a bamboo stick if caught punishment.

scttgrd
01-14-2008, 06:27 PM
Increased maket share will only make the bullseye on Apple O/S larger, and the reputation as being difficult to exploit will be a challenge for hackers. Not enough users yet to get them interested just yet.

Orange_Beard
01-14-2008, 06:48 PM
This is news?

PaintballCLE
01-14-2008, 11:26 PM
there is a patch out there for vista...... you dont need an actual patch from apple....... the vista one will atuomatically disable the buffer overflow.........wow at least there is One good thing going for vista

sixtimeseight
01-15-2008, 12:00 PM
But But Appples R Perfect, Thaey Cant Get Virusis N Stuff!!!11

Sim Pilot 4.0
01-15-2008, 01:23 PM
But But Appples R Perfect, Thaey Cant Get Virusis N Stuff!!!11

This list gives a slight glimpse of problems that happen with MAC's http://docs.info.apple.com/article.html?artnum=61798

If you have version 7.3.1 of quicktime you should be ok

Beantown Bronco
01-15-2008, 02:05 PM
This list gives a slight glimpse of problems that happen with MAC's http://docs.info.apple.com/article.html?artnum=61798

If you have version 7.3.1 of quicktime you should be ok

Pretty short list considering it includes multiple apple products (not just Macs) and extends over three years.

Go check out the recall/service bulletin list on any manufacturer of new cars over the last three years and you'll be looking at pages and pages of problems.....even among the most reliable manufacturers.

Bronx33
01-15-2008, 02:55 PM
http://www.apple.com/quicktime/download/

update

Maximus
01-15-2008, 07:45 PM
I just updated my Iphone and computer. The Iphone has some cool New features!

* The ability to send an SMS message to multiple people
* Google Maps application can now pinpoint your location using cell tower triangulation
* Google Maps can now display the Hybrid map view
* You can now drag and drop application icons on your home screen
* The home screen supports pagination
* You can now add web bookmarks to your home screen

Maximus
01-15-2008, 07:57 PM
Holy crap triangulation actually works!!!