Cell Phone Forums > Cell Phone Manufacturers > Apple » Zero-day exploit in QuickTime could hit Win iTunes users


Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 11-28-2007, 07:27 PM
cellphoner's Avatar
RSS Bot
 
Join Date: Feb 2007
Posts: 3,933
Zero-day exploit in QuickTime could hit Win iTunes users

Filed under: Security
Over the weekend, security researchers announced a vulnerability in QuickTime's handling of the RTSP streaming protocol, and Windows-only exploit code is already circulating. The flaw allows attackers to craft specially formatted RTSP responses that cause a buffer overflow, and as a result they can execute arbitrary code in the context of the logged-in user. Unfortunately, there are plenty of ways to get someone to click a malicious RTSP link, including sending it in email or including it on a website. While Symantec notes that IE and Safari for Windows appear to be resistant to the exploit code, opening a malicious RTSP link in current versions of Firefox or in QuickTime Player would allow the exploit to run.

For now, there is no Mac version of the exploit (cold comfort to the millions of iTunes for Windows users); hopefully there will be a QuickTime security patch on both platforms before any additional exposure occurs. Rich Mogull at TidBITS has some helpful tips for securing your network, including blocking the RTSP protocol both at the firewall and for outbound connections via Little Snitch.

[via TidBITS]

Read | Permalink | Email this | Comments


</img> </img>


More...
Digg this Post!
Reply With Quote
  #2  
Old 11-29-2007, 09:09 AM
fred333's Avatar
Whats A Cell Phone?
 
Join Date: Nov 2007
Location: Rochester, NY
Posts: 7
Thanks for the update. I hate when I get viruses and adware. Such a pain to deal with.
Digg this Post!
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Automatic Translations made by Google:
Albanian Arabic Bulgarian Catalan Chinese Croatian Czech Danish Dutch English Estonian Filipino Finnish French Galician German Greek Hebrew Hindi Hungarian Indonesian Italian Japanese Korean Latvian Lithuanian Maltese Norwegian Persian Polish Portuguese Romanian Russian Serbian Slovak Slovenian Spanish Swedish Taiwanese Thai Turkish Ukrainian Vietnamese