News, info, and opinion by Mac users, for Mac users.

November 27, 2007

security

Quicktime has a security flaw… again

Posted Nov. 27, ’07, 5:15 AM PT by Derik DeLong
Category | Security

Bad Quicktime Security Before you get concerned, the buffer overflow exploitation is currently only confirmed on Windows. A malformed Content-type header in RTSP media could trigger a buffer overflow that could lead to arbitrary code execution. To make matters worse, Apple doesn’t take advantage of the ASLR (Address Space Layout Randomization) so exploiting this is even worse.

It’s currently unknown if the problem is also present in the Mac version of Quicktime, or if it is, it’s exploitable. Even if it’s not, I’m just not happy with Apple about this. Quicktime has become the recurring joke of Apple’s security record. As a media playing framework, it should be safe to be installed and used.

It’s time to shape up. It’s just embarrassing.


1 Comments

Dave-O said:

You'd think a piece with that tone would forego such obvious errors as misplaced modifiers. Let he who is without sin... and all. The opening line screams "fix me" on the first reading.

To be more constructive, one might suggest that Quicktime is long overdue for a security audit.

Leave a comment

 




Visit other IDG sites: