toggle

AAPL Stock: 497.67 ( 0 )

QuickTime among most vulnerable Windows apps

updated 02:50 pm EDT, Fri November 2, 2007

QuickTime vulnerable


According to security vendor Bit9, QuickTime is among the most security flaw-ridden Windows applications. Apple's media player ranks second on the list of programs that are difficult for an IT department to patch and/or "represent unexpected and unquantified vulnerabilities in an enterprise IT environment." Another Apple product, iTunes, appears at number 6. Meanwhile, according to a ZDNet report, Yahoo's standalone IM client, Yahoo Messenger, is number one on the list. Microsoft has only one entry on the list: Windows Live MSN Messenger at #4.

Bit9 explained why Microsoft's products, though subject to a number of flaws, do not factor highly in the list: "The reason most Microsoft software doesn’t make the list is because by now most companies have a pretty good process in place for identifying, patching, and fixing vulnerable Microsoft software. The same cannot be said for apps like Firefox, iTunes, and other packages."

Apple's generally stellar security reputation has been under fire lately. A new trojan horse designed specifically for Mac OS X systems has been discovered on several pornography websites that can hijack Web traffic, according to security firm Intego. Affected systems are used to hijack some Web requests that lead users to other phishing sites, or simply display ads for other pornographic websites to generate ad revenue.

In addition, Mac OS X Leopard is not fundamentally better for security than Tiger, several security experts suggest. Thomas Ptacek of Matasano Security writes that Leopard's new security features, though an improvement, still leave unnecessary gaps open. Library Randomization is meant to solve problems such as buffer overflow attacks, by preventing hackers from knowing where to place a code in memory; the equivalent of this in Windows Vista is Address Space Load Randomization.


by MacNN Staff

TAGS :

 Apple
toggle

Comments

  1. coldfusion1970

    Fresh-Faced Recruit

    Joined: Nov 2004

    0

    switchers

    Couldnt they solve their security problems by switching to Macs?

  1. dscottbuch

    Fresh-Faced Recruit

    Joined: Sep 2000

    0

    Ridiculous

    So, even if other MS products are 10 times worse that QT they don't make the list because those applications are known to be that way????????? What a farce this whole security industry is!!!!!

  1. climacs

    Fresh-Faced Recruit

    Joined: Sep 2001

    0

    translation

    "The reason most Microsoft software doesn’t make the list is because by now most companies have a pretty good process in place for identifying, patching, and fixing vulnerable Microsoft software."

    translates to: "we're not counting MS software because people are pretty used to the fact that it's full of holes and they have to devote a significant amount of time and effort to constantly patching it."

    or, "we can't afford to piss off Microsoft so we're peddling this FUD."

    what a joke.

  1. climacs

    Fresh-Faced Recruit

    Joined: Sep 2001

    0

    huh?

    "represent unexpected and unquantified vulnerabilities in an enterprise IT environment."

    what does that mean???

    by that definition, of course MS doesn't make the list. MS software is expected to be vulnerable, with great quantities of security holes.

    idiots.

  1. eggman

    Mac Enthusiast

    Joined: Aug 2002

    0

    Pathetic

    Outlook has to be Public Enemy Number One when it comes to security issues, with ActiveX vying for the title.

    But because they're well known threats, they get cut out of the list?

  1. testudo

    Fresh-Faced Recruit

    Joined: Aug 2001

    0

    Re: huh?

    "represent unexpected and unquantified vulnerabilities in an enterprise IT environment."

    what does that mean???


    It means exactly what it says. The point of the article/release was to document the unknown/unexpected, not the known. As they say, MS is a known quantity. IT departments know all about it, MS knows all about it, everybody knows all about it. And whether you like it or not, MS has a much better framework for dealing with issues then Apple or a lot of other vendors do.

    by that definition, of course MS doesn't make the list. MS software is expected to be vulnerable, with great quantities of security holes.

    That's correct. Again, this is to inform the IT departments of what they might NOT know, not what they already know. Talk about a waste of time. "Hey, let's list all the MS software that's got security issues with it!" (a shorter waste of time would be to detail the ones that don't).

    idiots.

    Only to those who don't know what the mission statement of this item was supposed to be. Oh, I'm sorry, that would be you. Ooops.

  1. testudo

    Fresh-Faced Recruit

    Joined: Aug 2001

    0

    iTunes

    I can understand Quicktime being on the list, but I've got a problem with iTunes. One, I don't recall security warnings for the software itself (although one must admit the software is a pain, being that its update cycle is like monthly). Two, and more importantly, what IT departments are spending their time installing iTunes on work computers? The way most IT people are, they only want to install what is necessary, not just any ol' app because Fred in Finance wants to listen to some online music...

  1. ender

    Junior Member

    Joined: Mar 1999

    0

    MCSE

    Sounds to me like a bunch of MCSE's (Microsoft Certified System Engineers) working to ensure job security by stating that MS products are more secure if you continue to pay us to maintain your systems for you.

  1. Flying Meat

    Fresh-Faced Recruit

    Joined: Jan 2007

    0

    wsus don't cut it

    so move to a more open product. It will pay to not lock your entire enterprise to "windows only" update and patch management solutions, since microsoft can't compete in every software channel.

    I doubt wsus (Windows Software Update Server) can adequately handle most 3rd party patch management adequately (not to mention other platforms), so since most enterprises have a need to employ these products, it behooves IT to broaden its scope.

    LANDesk, or a similar very-nearly enterprise product would cover most companies. LANrev would cover the nearly all the rest.

    Nothing pisses a user off more than a whiney I.T. department. >:|

  1. Flying Meat

    Fresh-Faced Recruit

    Joined: Jan 2007

    0

    re: iTunes

    iTunes is becoming an integral visual media product for both .edu, and .com spaces. It is undeniably popular with the general user space, and certainly handles the bulk of disparate protocols, so why wouldn't I.T. support it?

    On the other hand, I am also unaware of iTunes attack vectors/vulnerabilities. Doesn't mean it can't/won't/hasn't happened, but I do try to stay abreast of such things in general...

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

10 Most Read

Recent Reviews

Logitech Cube

The world of mice could often be described charitably as stagnant: it's an endless sea of ergonomic shapes that assume you're sitting ...

NewerTech and Targus USB Hubs For Gifts

A useful holiday present to resolve an ongoing frustration is a multi-port hub. Whether as a stocking stuffer, Chanukah present, or an ...

X-Rite ColorMunki Photo

Color calibration is the art of tweaking your monitor so that the colors represented on screen better match real life and your printer ...

toggle

Most Commented

10 Most Discussed