Before you get concerned, the buffer overflow exploitation is currently only confirmed on Windows. A malformed Content-type header in RTSP media could trigger a buffer overflow that could lead to arbitrary code execution. To make matters worse, Apple doesn’t take advantage of the ASLR (Address Space Layout Randomization) so exploiting this is even worse.
It’s currently unknown if the problem is also present in the Mac version of Quicktime, or if it is, it’s exploitable. Even if it’s not, I’m just not happy with Apple about this. Quicktime has become the recurring joke of Apple’s security record. As a media playing framework, it should be safe to be installed and used.
It’s time to shape up. It’s just embarrassing.
Ch-ch-ch-ch-changes afoot at MacUser
The Macalope Weekly: Leopards and monopolies and DRM! Oh, my!
Apple levels DMCA on iPodhash project
iPod touch users get second classed again with the omission of new Maps features
Apple Pro Applications Update 2008-004 makes your day
iTunes v8.0.2 comes riding on the coattails of iPhone firmware v2.2
MacUser is your source for news, info, and opinion about Apple, the Mac, and the iPod. Our dedicated team of bloggers covers everything that is relevant to Mac users — and, okay, some stuff that’s not quite relevant, but is still a lot of fun.
You'd think a piece with that tone would forego such obvious errors as misplaced modifiers. Let he who is without sin... and all. The opening line screams "fix me" on the first reading.
To be more constructive, one might suggest that Quicktime is long overdue for a security audit.