MoAB flaw makes Flip4Mac flip E-mail
by Stephen Withers   
Sunday, 28 January 2007
The Flip4Mac QuickTime components - popular among Mac OS X users as they allow playback of Windows Media files - include an exploitable bug, according to the Month of Apple Bugs.

A maliciously crafted WMV file containing an invalid ASF_File_Properties_Object size field is not correctly handled by Flip4Mac. Instead, memory corruption occurs in a situation that can lead to arbitrary code execution, Kevin Finisterre and LMH claimed.

"[E]xploitation for arbitrary code execution is clearly possible," they wrote, adding that a "working exploit for this issue might be developed later today and released as soon as it's been tested and known to be reliable."

MoAB recommends disabling Flip4Mac (or at least the automatic opening of WMV files) until a fixed version is provided by Telestream. {moscomment}
Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter