Go Back   Cell Phone Forums > Cell Phone Manufacturers > Apple

Notices

Reply
 
LinkBack Thread Tools Display Modes
Old 11-28-2007, 08:27 PM   #1 (permalink)
RSS Bot
 
cellphoner's Avatar
 
Join Date: Feb 2007
Posts: 3,918
Zero-day exploit in QuickTime could hit Win iTunes users

Filed under: Security
Over the weekend, security researchers announced a vulnerability in QuickTime's handling of the RTSP streaming protocol, and Windows-only exploit code is already circulating. The flaw allows attackers to craft specially formatted RTSP responses that cause a buffer overflow, and as a result they can execute arbitrary code in the context of the logged-in user. Unfortunately, there are plenty of ways to get someone to click a malicious RTSP link, including sending it in email or including it on a website. While Symantec notes that IE and Safari for Windows appear to be resistant to the exploit code, opening a malicious RTSP link in current versions of Firefox or in QuickTime Player would allow the exploit to run.

For now, there is no Mac version of the exploit (cold comfort to the millions of iTunes for Windows users); hopefully there will be a QuickTime security patch on both platforms before any additional exposure occurs. Rich Mogull at TidBITS has some helpful tips for securing your network, including blocking the RTSP protocol both at the firewall and for outbound connections via Little Snitch.

[via TidBITS]

Read | Permalink | Email this | Comments


</img> </img>


More...
cellphoner is offline  
Digg this Post!
Reply With Quote
Old 11-29-2007, 10:09 AM   #2 (permalink)
Whats A Cell Phone?
 
fred333's Avatar
 
Join Date: Nov 2007
Location: Rochester, NY
Posts: 7
Thanks for the update. I hate when I get viruses and adware. Such a pain to deal with.
fred333 is offline  
Digg this Post!
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 10:12 AM.

Design By: TransverseGFX
Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 copyright phonetweaks.com 2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72