Security hole found in QuickTime
Posted on 27 Nov 2007 at 09:27
A security researcher has discovered an "extremely critical" flaw in QuickTime for Windows XP.
QuickTime 7.3's handling of the Real Time Streaming Protocol (RTSP) can be exploited to compromise a user's system, says Krystian Kloskowski, who has developed, but not published an exploit.
The vulnerability is caused due to a boundary error when processing RTSP replies, which can be exploited to cause a stack-based buffer overflow, explains security firm, Secunia.
Successful exploitation allows execution of arbitrary code, though execution requires that the user is persuaded or tricked into opening a malicious QTL file or visiting a malicious website.
Kloskowski discovered the flaw in QuickTime Player 7.3 running on Windows XP SP2, but further investigation by Symantec reveals that the vulnerability is restricted to specific browsers, most notably Firefox - with Internet Explorer 6/7 and Safari 3 Beta the attack is prevented.
The US Computer Emergency Readiness Team (US-CERT) has published a number of workarounds that may help to prevent exploitation, though they may hamper normal computer usage.
Until Apple releases a fix, users are best advised to follow Secunia's advice and standard good practice: do not browse untrusted websites, follow untrusted links or open untrusted QTL files.
Author: Simon Aughton
advertisement
- Motorola pays Lucas for its Droid
- Where are the killer apps for Windows?
- Will you hit the Orange iPhone "unlimited" cap?
- USB 3 first benchmark - it's here, and it's fast
- Why Windows 7 has forced me to worry about security
- How Dixons is (under)selling Windows 7
- Do I like Windows 7 because it's so like a Mac?
- No Windows 7 drivers turn Dell M1330 into a doorstop
- Is Windows 7 good looking enough to sway an Apple fan?
- Typekit brings print-like typography to the web
- Avira Premium Security Suite 9
- ZoneAlarm Internet Security Suite
- Webroot Internet Security Essentials
- Trend Micro Internet Security
- PC Tools Internet Security 2009
- Panda Internet Security 2009
- Norton Internet Security 2009
- Kaspersky Internet Security 2009
- F-Secure Internet Security 2009
- Eset Smart Security
- BitDefender Total Security 2009
advertisement

Printed from www.pcpro.co.uk

