And in the category of Most Vulnerable Apple Software Package, the winner is…QuickTime. It was a mere two days ago that a hole in QuickTime’s RTSP headers was announced, and now we have more detail on the problem. It is now confirmed, however, that the vulnerability seems to affect both Windows and OS X (that’s Tiger and Leopard, PowerPC and Intel). Oh, joy.
The exploit is laid out in staggering detail in a two-part blog post on Subreption, along with a list of factors that could help mitigate this vulnerability were they deployed in OS X. The upshot, though, is that a maliciously-crafted QuickTime movie could execute arbitrary code, due to a stack-based buffer overflow. That’s computerspeak for “whoopsie.”
Seems likely Apple is working on a patch, so don’t be surprised if a Security Update appears in your Software Update window sometime in the next few days.
[via The Register]
Ch-ch-ch-ch-changes afoot at MacUser
The Macalope Weekly: Leopards and monopolies and DRM! Oh, my!
Apple levels DMCA on iPodhash project
iPod touch users get second classed again with the omission of new Maps features
Apple Pro Applications Update 2008-004 makes your day
iTunes v8.0.2 comes riding on the coattails of iPhone firmware v2.2
MacUser is your source for news, info, and opinion about Apple, the Mac, and the iPod. Our dedicated team of bloggers covers everything that is relevant to Mac users — and, okay, some stuff that’s not quite relevant, but is still a lot of fun.
Wow this comes at a bad time. Tomorrow I am switching away from Windows as I'll be heading down to my local Apple store and purchasing a brand spanking new Macbook. I guess I'll just download VLC player and use it instead. I'm so excited that I'm getting a Macbook tomorrow I can hardly sit still.