Technology news and Jobs arrow Information Technology News arrow Another month, another QuickTime vulnerability
Another month, another QuickTime vulnerability E-mail
by Stephen Withers   
Monday, 14 January 2008
Deliberately malformed media files and streams have proved successful ways of taking control of computers, so it's not surprising that malware writers and security researchers continue to target software involved in their playback.

The latest issue to arise is (yet another) buffer overflow exploit, once again targeting QuickTime's Real-Time Streaming Protocol (RTSP) code.

Dozens of QuickTime flaws were corrected by Apple during 2007, and the most recent update addressed another RTSP issue.

The new flaw was revealed by Luigi Auriemma, who said both Mac and Windows versions of QuickTime 7.3.10 and earlier. It occurs in the handling of HTTP error messages, and can be exploited with an RTSP link to a server that has port 554 closed, causing QuickTime to retry the request using HTTP on port 80. If the server sends a maliciously crafted error message in response to the HTTP request, QuickTime will display in the status area of the player window, triggering the flaw and allowing the execution of code contained in the message.

Blocking such attacks in the absence of a fix for the underlying problem is not simple, though US-CERT has made several suggestions.

Uninstalling QuickTime is not practical for most users, and blocking all RTSP traffic at the the firewall would cut off much streaming media.

Changing the RTSP handler to another application is feasible, but you'd need to identify one that has plugged all known vulnerabilities otherwise you would be no better off.

Please enable JavaScript in your browser to post your comment!


Get stories like this delivered daily - FREE - subscribe now
 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
Suscribers
904,266
13,751
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff
Subscribe to our free e-newsletter