• On The Insider: Bruno Film Edited Due to Jackson's Death

November 4, 2005 9:17 AM PST

Apple sounds alarm over QuickTime flaws

  • 24 comments
Apple Computer late Thursday issued an alert about flaws in its QuickTime media player that could allow a malicious attacker to launch a denial-of-service attack or remote code execution.

QuickTime versions 6.5.2 and 7.0.1 for the Mac OS X operating system are affected by the vulnerabilities, as well as some versions for Microsoft Windows, according to a Friday report by security company Secunia, which rated the vulnerabilities "highly critical."

Apple has issued an update, QuickTime 7.0.3, to fix the four flaws. The patch was posted to Apple's Web site on Oct. 12.

One vulnerability can result in a denial-of-service, or DOS, attack against any application loading remotely originated content. The flaw involves a missing movie attribute, which is interpreted as an extension. The absence of the actual extension, however, is not detected, resulting in a "dereference of a null pointer," Apple warned.

Another security hole involves an integer overflow that may be remotely exploited through a specially crafted video file. This could lead to an arbitrary execution of code.

"Three of the vulnerabilities can launch malicious code that allows an attacker to snoop on users," said Thomas Kristensen, Secunia's chief technology officer. "The other vulnerability is a DOS attack that will only work in a few cases and crash the media player when it tries to open a file."

Last June, Apple released QuickTime 7.0.1 to address a security flaw and deliver several improvements to its media player. The update was designed to modify the Quartz Composer plug-in, which previously could allow an attacker to tap into local data and distribute it to an arbitrary Web site.

See more CNET content tagged:
denial of service, Apple QuickTime, flaw, vulnerability, Apple Computer

Add a Comment (Log in or register) (24 Comments)
  • prev
  • 1
  • next
Secunia "reporting" flaws weeks after they're fixed...
by M C November 4, 2005 10:30 AM PST
QuickTime 7.0.3 was released October 12.

That's one on-top-of-it security company.
Reply to this comment
Where is everybody?
by J_Satch November 4, 2005 10:31 AM PST
Where are Ty and Sheldon to tell us, respectively, how there can be no flaws in Apple products and how OS/2 can save us all from ourselves? LOL
Reply to this comment
Quiet
by Rolndubbs November 4, 2005 10:40 AM PST
According to Ty, this never happend, and soon will be forgotten. :)
View all 3 replies
I know...
by NeverFade November 4, 2005 11:34 AM PST
I know what you mean. Ty is a mac zealot, and actually does make
the regular user of macs look bad. I, myself use a mac, and very
much enjoy working in OSX. I know PC people have their own
zealots along with Macs... so we'll deal with it I guess.

Macs do have their flaws, just not as much as some other OS's IMO.
This QT flaw has been fixed a few weeks ago, however, and now
apparently are just telling us how important the upgrade is.
View all 2 replies
This is not a OS problem
by R. U. Sirius November 4, 2005 2:26 PM PST
I'm a PC user, but be that as it may...

For those who wish to enage in bashing, which I do not wish to do, be aware that this is not an OSX problem (read the article again). Quicktime is a cross platform tool, so the better comparison is to Windows Media Player. As the article states, the problem exists across platforms.
Reply to this comment
Highly Critical?
by open-mind November 4, 2005 5:46 PM PST
Software Update upgraded my Quicktime as needed weeks ago.

Not heard of any exploits of this.

Doesn't sound that critical. Good free PR for Secunia though.
Reply to this comment
According to the standard practice, yes
by Hernys November 4, 2005 9:04 PM PST
The criticality of a vulnerability doesn't depend on the availability of a patch. If you have a patch installed, then you don't have the vulnerability, period. But if you don't have the patch, the vulnerability is critical, it doesn't matter if the patch exists or not.
RULE # 1
by November 5, 2005 2:39 AM PST
Just to repeat my rules of software -
RULE # 1 - ALL SOFTWARE HAS FAULTS - except the stuff I write :-)

But I personally have NEVER been inconvenienced by any virus or any vunerability in Wintel or Mac. I just keep my security up to date & I'm fine. So, from my perspective - OS X & XP Pro are both just fine. I wouldn't choose one over the other based on security, because I can make both secure.
Reply to this comment
inconvenienced
by Thunder Johny June 19, 2007 10:13 AM PDT
http://www.analogstereo.com/mitsubishi_lancer_owners_manual.htm
apple ONLY CLAIMS to be the safest
by Buckeroo November 7, 2005 10:08 AM PST
Alright, I've been in computer repairs for many years. Apple users always claim that apple computer software does not have any faults and viruses. Wrong. I have numerous cases of macs infected with viruses and numeerous faults with apple software (if everyting works dandy, why the need for 'Force Quit' menu? Something tells me it's the same thing as Ctrl Alt- Del in Windows). Also, noticing that Apple's compose of only 3% of all computers, these flaws aren't noticed, but if apple get bigger, then we'll see the same thing as Microsoft--someone somewhere will find security holes in apples too.
Reply to this comment
More Detail Please?
by open-mind November 7, 2005 10:41 AM PST
Any info/links to these Mac viruses? I'm curious about their name/behavior etc. Thanks.

In response to your question...

Force Quit lets the user stop a "locked" application that is no longer responding to normal user inputs. Kind of like "End Task" in Windows.
(24 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Apple (1.58%) 2.16 138.52
Dow Jones Industrials (-0.45%) -36.65 8,146.52
S&P 500 (-0.40%) -3.55 879.13
NASDAQ (0.20%) 3.48 1,756.03
CNET TECH (0.36%) 4.57 1,262.65
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right