QuickTime RTSP Vulnerability Proof-of-concept Surfaces

· by · News

A few days after a flaw was discovered in the QuickTime handling of the Real Time Streaming Protocol (RTSP), researchers have been able to craft a proof-of-concept exploit, according to Computerworld on Thursday.

"This particular exploit can cause remote code execution through the QuickTime RTSP protocol vulnerability on Microsoft Windows and Apple systems," Symantec said. "This is the first working exploit for Apple systems that we have observed."

The appearance of a proof-of-concept exploit at the site milw0rm.com has be characterized as a "tripwire" by Symantec. "Once we see something in Metasploit, we know itis likely weill see it used in attacks," Alfred Huger, vice president of engineering with Symantecis security response group said last summer.

The proof-of-concept works on Intel or PPC Macs running Tiger or Leopard with QuickTime 7.2 or 7.3 (It also affects Windows XP SP2.) Symantec explained how it might work along with some preventive measures.

Apple has not yet published a fix.

John Martellaro

John Martellaro

John Martellaro was born at an early age and began writing about computers soon after that. He is a former U.S. Air Force officer and has worked for NASA, White Sands Missile Range, Lockheed Martin Astronautics, the Oak Ridge National Laboratory and Apple. At Apple he worked as a Senior Marketing Manager, a Federal Account Executive and a High Performance Computing manager. His interests include skiing, chess, science fiction and astronomy. You can follow John on Twitter at twitter.com/jmartellaro.

Sign Up for the Newsletter

Enter a valid email address

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday.

Adding to list…

No Comments

Log-in to comment