RSS RSS Twitter Twitter
macnn

09/18/2008, 9:25am, EDT

Thursday, September 18th

Vulnerability discovered in QuickTime 7.5.5

A possible security hole has been discovered in QuickTime 7.5.5, which was released last week alongside iTunes 8. Symantec researcher Aaron Adams notes that a particular parameter in QuickTime is not geared to cope with strings past a certain length, and that if this trait were to be properly exploited, it could represent a security threat. "Symantec is currently investigating this flaw further to determine the underlying technical details," Adams' official note reads.

Present testing has only been able to force QuickTime to crash, but it is believed that the potential exists to run arbitrary code, which if true could cause significant danger to QuickTime users. An interested hacker could embed a malicious file onto a website, and launch an attack with minimal interaction on the part of the victim.

Adams suggests that there is currently no real defense against such an attack, beyond avoiding suspicious websites or disabling the QuickTime plug-ins of various browsers.


Filed under: security, software, Apple
Other story tags: QuickTime

, , 11comments, del.icio.us, slashdot, digg, buzz , Twitter



11 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All
   Global Settings

Ohh, disable it?

2
09/18, 9:38am, EDT

Come on - you point to a POTENTIAL issue where QT crashes. Ok, that's a bad thing, all that crashing, but it 'just' crashes.

Come back when you actually have a security hole!

Forum Regular
Joined May 1999
User is offline

End of financial quarter

2
09/18, 9:46am, EDT

Time to sell a few more copies of Symantec before the quarter ends, eh?

IF QT does this, and IF a malicous hacker does that, and then IF he puts it on his website which I will NEVER visit because I only surf where I choose to surf and not out on some hackers website looking for pictures of Brad Pitt, and IF I then download it, and IF I am not on a Mac and then IF it crashes my QT then I will just break down and cry and probably end my life over QT crashing.

Give me a break. Enough with the scare tactics. Go sell your software to someone who needs it.... the ever-dwindling pool of idiots using Windoze products.

Fresh-Faced Recruit
Joined Oct 2006
User is offline

Let the FUD begin!

2
09/18, 10:23am, EDT

Hmmm...somebody from a company that produces anti-virus software warns of a possible threat.

Fuck off!

Fresh-Faced Recruit
Joined Jan 2002
User is offline

fools

-3
09/18, 11:38am, EDT

You all don't know what the hell you're talking about. First, the guy was actually responding to a posting of the issue on a hacker web site. I guess you all just don't care, but at least Symantec responded (let's see how long before Apple responds to the information).

And neither say a security problem exists. It suggests a problem does exist (which it does), but so far they've not yet proved that it could be used to execute arbitrary code.

Oh, and it also is a Mac and Windows issue.

BTW, jhawk, Symantec doesn't check for this flaw, so there's no need to buy the software in the first place.

And if it were something in Windows Media Player or IE, you'd be laughing up a storm, not saying "Yeah, but who goes to some hacker website and view a video.".

Mac users: The set of people who believe information is useless, and security is built-in and not a concern. Gotta love them!

Fresh-Faced Recruit
Joined Aug 2001
User is offline
nat

he just never tires

2
09/18, 11:55am, EDT

i suppose his constant bashing of all things apple is because he has absolutely nothing better to do. as in nothing at all whatsoever.

and we're the fools. i like it so much better when he disappears for long periods of time. but then he comes back with the EXACT SAME MO EVERY SINGLE TIME. repeating, ad nauseam, the same thing OVER AND OVER AND OVER AND OVER AND OVER AND OVER...

testudo, my dear boy, WE DON'T GIVE A F&*K. are you really so stupid?

Junior Member
Joined Mar 2002
User is offline

Legacy

3
09/18, 1:29pm, EDT

QuickTime has about 20 years worth of legacy code and needs to be completely rewritten using the modern Cocoa frameworks from the ground up. I hope QuickTime X in Snow Leopard is just such a thing, instead of putting lipstick on a pig.

Fresh-Faced Recruit
Joined Jul 2005
User is offline

never tires

-4
09/18, 3:19pm, EDT

Well, posters here never tire of the stupid "Oh, its just a virus company trying to scare people" rants. But they're OK?

And the only bashing of Apple I did was to comment on the fact Apple will NOT comment on this issue. In fact, if Symantec didn't pick it up, the only ones knowing about it would probably be the hackers themselves.

But, I know, hackers aren't problems. They're good people.

Fresh-Faced Recruit
Joined Aug 2001
User is offline

Testicular

1
09/18, 6:11pm, EDT

I mean Testudo... show me one virus or trojan that has penetrated any Mac runing any version of OS X, any iPod or any iPhone...


NONE EXIST in the Wild.

So Shut The FCUK up already!

Fresh-Faced Recruit
Joined Oct 2006
User is offline

Are you people serious?

2
09/19, 4:59am, EDT

This is a buffer overrun. This is not a little problem. This is the type of problem that can be exploited by novice hackers. Buffer overruns allow malicious users to plant trojans, keyloggers, and potentially take control of your machine.

Mac users really need to understand that OS X is great and Mac is awesome, but the more market share Mac gets, the more it is going to be subject to exploits.

http://www.scmagazineus.com/QuickTime-exploit-disclosed-for-1-week-old-version/article/118154/

These guys are already discussing how to exploit it:
http://forums.remote-exploit.org/showthread.php?t=17024

The National Vulnerability Database lists it as a high severity impact:
http://web.nvd.nist.gov/view/vuln/detail;jsessionid=9cd57844ed038040099c12069cd1?execution=e1s1

It's not a matter of Mac bashing, it's just a matter of being aware that there are actually real vulnerabilities in every operating system. It's not a put-down, it's a warning.

Fresh-Faced Recruit
Joined Sep 2008
User is offline

DNSChanger

-1
09/19, 11:28pm, EDT

jhawk95 said...

"I mean Testudo... show me one virus or trojan that has penetrated any Mac runing any version of OS X, any iPod or any iPhone...

NONE EXIST in the Wild.
So Shut The FCUK up already!"
--------------------------------------------
This one is still in the wild and has bitten many Mac users:

http://www.f-secure.com/v-descs/trojanosxdnschanger.shtml

FACT.

Fresh-Faced Recruit
Joined Sep 2008
User is offline
additional comments:..1..2..Next
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News
Want To Sell Your Laptop? Any Condition - receive Top Cash. Get an instant quote. Free shipping www.CashForLaptops.com

Internet Marketing School - 100% Online: Master SEO, SEM, E Commerce, Media & More with a U of San Francisco Certificate.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.