IT NEWS     Sustainability    Get JOB ALERTS that match your skills
Technology news and Jobs arrow Information Technology News arrow QuickTime RTSP vulnerability goes wild
QuickTime RTSP vulnerability goes wild PDF E-mail
User Rating: / 2
PoorBest 
by Stephen Withers   
Monday, 03 December 2007
The QuickTime RTSP vulnerability disclosed last week is now being exploited in the wild.
According to Symantec, "Our current analysis is also leading us to believe that there may be multiple attacks in existence. Further investigation is currently under way to confirm this."

The confirmed attack uses an IFRAME to redirect browsers to the site hosting the malicious code.

"Since a patch to correct the issue has yet to be released, we advise users to be cautious when browsing the web," said Joji Hamada, security response engineer at Symantec.

In related news, an analysis performed by tech startup Subreption has found that the vulnerability can be exploited on Mac OS X as well as Windows. By determining the operating system and QuickTime version running on the target computer, a malicious server can deliver the appropriate exploit.

Subreption says the lack of heap randomisation, the ability to execute stack memory on the PowerPC version of Mac OS X, and the ability to make stack memory executable on the Intel version all make it easier to exploit the flaw.

Mac security vendor Intego has claimed that "any exploit that targets a Windows computer will also affect Macs." Apart from the relatively trivial case of an exploit intended only to crash QuickTime, this may not be true. While the vulnerability may be cross-platform, an exploit would need to be targeted to an operating system. That said, writing an exploit that takes advantage of a shared vulnerability to deliver system-specific payloads is an established technique.

Please enable JavaScript in your browser to post your comment!


Get stories like this delivered daily - FREE - subscribe now
 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
Suscribers
802,938
13,641
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff
Subscribe to our free e-newsletter
First name:
Last name:
Your email address:
Your role:
Your industry:
Australian state:
Country:
Enter the security code shown:
mandatory