Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.
Deliberately malformed media files and streams have proved successful ways of taking control of computers, so it's not surprising that malware writers and security researchers continue to target software involved in their playback.
The latest issue to arise is (yet another) buffer overflow exploit, once again targeting QuickTime's Real-Time Streaming Protocol (RTSP) code.
Dozens of QuickTime flaws were corrected by Apple during 2007, and the most recent update addressed another RTSP issue.
The new flaw was revealed by Luigi Auriemma, who said both Mac and Windows versions of QuickTime 7.3.10 and earlier. It occurs in the handling of HTTP error messages, and can be exploited with an RTSP link to a server that has port 554 closed, causing QuickTime to retry the request using HTTP on port 80. If the server sends a maliciously crafted error message in response to the HTTP request, QuickTime will display in the status area of the player window, triggering the flaw and allowing the execution of code contained in the message.
Blocking such attacks in the absence of a fix for the underlying problem is not simple, though US-CERT has made several suggestions.
Uninstalling QuickTime is not practical for most users, and blocking all RTSP traffic at the the firewall would cut off much streaming media.
Changing the RTSP handler to another application is feasible, but you'd need to identify one that has plugged all known vulnerabilities otherwise you would be no better off.
David Frost
| SYDNEY– February 9, 2012. Gigamon®, the world leader in Traffic Visibility Fabric solutions, announced that it has expanded the breadth and s…
How to Make Business Discovery Work for Your Business
Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more
Try an easy-to-use set of web-enabled
tools for business-class productivity services. Office 365 provides
anywhere-access to email, important documents, contacts, and calendars
on almost any device.