Quantcast
MacUser
News, info, and opinion by Mac users, for Mac users.

Quicktime has a security flaw… again

Posted by Derik DeLong | Tuesday, November 27, 2007 5:15 AM PT

Bad Quicktime Security Before you get concerned, the buffer overflow exploitation is currently only confirmed on Windows. A malformed Content-type header in RTSP media could trigger a buffer overflow that could lead to arbitrary code execution. To make matters worse, Apple doesn’t take advantage of the ASLR (Address Space Layout Randomization) so exploiting this is even worse.

It’s currently unknown if the problem is also present in the Mac version of Quicktime, or if it is, it’s exploitable. Even if it’s not, I’m just not happy with Apple about this. Quicktime has become the recurring joke of Apple’s security record. As a media playing framework, it should be safe to be installed and used.

It’s time to shape up. It’s just embarrassing.

Comments (1)

You'd think a piece with that tone would forego such obvious errors as misplaced modifiers. Let he who is without sin... and all. The opening line screams "fix me" on the first reading.

To be more constructive, one might suggest that Quicktime is long overdue for a security audit.

Dave-O
November 27, 2007
2:00 PM PT

Archives

Categories