No. 1 Story

Construction needs cloud flexibility

Australia’s embattled construction sector could benefit from cloud based information systems that can be switched on and off in lockstep with individual projects – with the exception of those organisations based in remote areas like the Kimberleys.

read more

Related Articles

Adoption of cloud computing has reached a tipping point  - but don’t expect legacy...
In yet another blow to the Facebook IPO this week, following the withdrawal of...
Recruitment technology and social media have played a significant role in growing business in...
It’s a bird, it’s a plane, no, it’s a super-speedy 4G LTE modem jumping...
Telstra came out on top in a mobile phone customer survey conducted by the...

'Month of Apple Bugs' #1 also hits Windows

Your IT - Home IT

LMH's 'Month of Apple Bugs' has kicked off with a description of a flaw in QuickTime's rtsp:// (Real Time Streaming Protocol) handler that allows the execution of arbitrary code.

According to the description, the flaw has been exploited in the Mac OS X and Windows versions of QuickTime 7.1.3 and "Previous versions should be vulnerable as well."

A specially-crafted URL contained within HTML, JavaScript or a QTL file can be used to take advantage of the flaw. A proof-of-concept is available via the above link.

Given that this is Yet Another Buffer Overflow, we wouldn't expect it too be particularly difficult for Apple to fix, but the advisory concludes that for now "The only potential workaround would be to disable the rtsp:// URL handler, uninstalling Quicktime or simply live with the feeling of being a potential target for pwnage."