Windows QuickTime Zero-day Flaw Discovered
January 10th, 2008 at 2:00 PM - News by Jeff Gamet
A new security flaw in QuickTime 7.3.1 for Windows surfaced on Thursday that apparently lets an attacker take control of remote PCs. The vulnerability was discovered by Italian security researcher Luigi Auriemma who posted proof-of-concept code for the exploit on the Internet, according to InformationWeek.
The alleged flaw takes advantage of a buffer overflow bug that lets an attacker send malicious code when QuickTime attempts to access a Real-Time Streaming Protocol link and port 554 on the server is closed.
Symantec Security Response claimed that the flaw appears to be legit. The companyis vice president of development, Alfred Huger, commented "The proof of concept code only managed to crash the product. But itis a safe assumption that if you can do that you may be able to execute remote code."
So far the flaw appears to impact only the Windows version of QuickTime, and to date there are no known instances of an actual attack based on the vulnerability. The likelihood that Windows users could see an actual attack based on Mr. Auriemmais sample code, however, is higher since he chose to publish his proof-of-concept before contacting Apple.
Recent Headlines - Updated February 9th
- Tue, 6:27 PM
- iPad - Apple Job Posting Hints at a Camera in Future iPads
- 6:22 PM
- Product News - Apple Releases Digital Camera RAW Compatibility Update 3.0
- 6:18 PM
- Product News - Apple Updates iLife ‘09 with Aperture 3 Support, Slideshow Performance
- 4:53 PM
- News - Google Introduces “Buzz” Social Information Sharing Service
- 4:19 PM
- Just a Thought - iPad: A Reason For Being
- 3:28 PM
- News - Google Lowers Nexus One “Equipment Recovery Fee” to $150
- 2:27 PM
- Deal Brothers - Refurbished 13” MacBook 2.13GHz Intel Core 2 Duo: $749
- 1:31 PM
- Jeff Gamet's Blog - Macworld Expo: It’s Our Show, Not Apple’s
- 10:38 AM
- Quick Look Review - Texas Tea for the iPhone and iPod touch
- 10:25 AM
- News - Apple Rolls Out Aperture 3 Video Tutorials
- 10:00 AM
- Hot Forum Topic - Backing Up Your iPhoto Library
- 9:35 AM
- Product News - Notebook, iThoughts Add TextExpander touch Support
The Mac Observer Reader Specials
- TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
RamJet Memory: Mac Pro 8GB Kit $275.99, Mac Pro 4GB Kits $145.99! Sale on MacBook and MacBook Pro 8GB kits $459.99! MacBook, MacBook Pro, iMac Mac mini 4GB Kits for $113.99! 1TB SATA Hard Drives for $109.99! Click here- If you own a car, you need CarMD! Catch problems, estimate repairs and more. Now for Mac. $98.99 at www.CarMD.com Save $10 with code TMO1.
If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.
Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.




