November 4, 2005 9:17 AM PST

Apple sounds alarm over QuickTime flaws

Apple Computer late Thursday issued an alert about flaws in its QuickTime media player that could allow a malicious attacker to launch a denial-of-service attack or remote code execution.

QuickTime versions 6.5.2 and 7.0.1 for the Mac OS X operating system are affected by the vulnerabilities, as well as some versions for Microsoft Windows, according to a Friday report by security company Secunia, which rated the vulnerabilities "highly critical."

Apple has issued an update, QuickTime 7.0.3, to fix the four flaws. The patch was posted to Apple's Web site on Oct. 12.

One vulnerability can result in a denial-of-service, or DOS, attack against any application loading remotely originated content. The flaw involves a missing movie attribute, which is interpreted as an extension. The absence of the actual extension, however, is not detected, resulting in a "dereference of a null pointer," Apple warned.

Another security hole involves an integer overflow that may be remotely exploited through a specially crafted video file. This could lead to an arbitrary execution of code.

"Three of the vulnerabilities can launch malicious code that allows an attacker to snoop on users," said Thomas Kristensen, Secunia's chief technology officer. "The other vulnerability is a DOS attack that will only work in a few cases and crash the media player when it tries to open a file."

Last June, Apple released QuickTime 7.0.1 to address a security flaw and deliver several improvements to its media player. The update was designed to modify the Quartz Composer plug-in, which previously could allow an attacker to tap into local data and distribute it to an arbitrary Web site.

24 comments

Join the conversation!
Add your comment (Log in or register)
Secunia "reporting" flaws weeks after they're fixed...
QuickTime 7.0.3 was released October 12.

That's one on-top-of-it security company.
Posted by M C (571 comments )
Reply Link Flag
Where is everybody?
Where are Ty and Sheldon to tell us, respectively, how there can be no flaws in Apple products and how OS/2 can save us all from ourselves? LOL
Posted by J_Satch (572 comments )
Reply Link Flag
Quiet
According to Ty, this never happend, and soon will be forgotten. :)
Posted by Rolndubbs (194 comments )
Link Flag
I know...
I know what you mean. Ty is a mac zealot, and actually does make
the regular user of macs look bad. I, myself use a mac, and very
much enjoy working in OSX. I know PC people have their own
zealots along with Macs... so we'll deal with it I guess.

Macs do have their flaws, just not as much as some other OS's IMO.
This QT flaw has been fixed a few weeks ago, however, and now
apparently are just telling us how important the upgrade is.
Posted by NeverFade (320 comments )
Link Flag
This is not a OS problem
I'm a PC user, but be that as it may...

For those who wish to enage in bashing, which I do not wish to do, be aware that this is not an OSX problem (read the article again). Quicktime is a cross platform tool, so the better comparison is to Windows Media Player. As the article states, the problem exists across platforms.
Posted by R. U. Sirius (745 comments )
Reply Link Flag
Highly Critical?
Software Update upgraded my Quicktime as needed weeks ago.

Not heard of any exploits of this.

Doesn't sound that critical. Good free PR for Secunia though.
Posted by open-mind (1027 comments )
Reply Link Flag
According to the standard practice, yes
The criticality of a vulnerability doesn't depend on the availability of a patch. If you have a patch installed, then you don't have the vulnerability, period. But if you don't have the patch, the vulnerability is critical, it doesn't matter if the patch exists or not.
Posted by Hernys (642 comments )
Link Flag
RULE # 1
Just to repeat my rules of software -
RULE # 1 - ALL SOFTWARE HAS FAULTS - except the stuff I write :-)

But I personally have NEVER been inconvenienced by any virus or any vunerability in Wintel or Mac. I just keep my security up to date & I'm fine. So, from my perspective - OS X & XP Pro are both just fine. I wouldn't choose one over the other based on security, because I can make both secure.
Posted by (409 comments )
Reply Link Flag
inconvenienced
<a class="jive-link-external" href="http://www.analogstereo.com/mitsubishi_lancer_owners_manual.htm" target="_newWindow">http://www.analogstereo.com/mitsubishi_lancer_owners_manual.htm</a>
Posted by Thunder Johny (201 comments )
Link Flag
apple ONLY CLAIMS to be the safest
Alright, I've been in computer repairs for many years. Apple users always claim that apple computer software does not have any faults and viruses. Wrong. I have numerous cases of macs infected with viruses and numeerous faults with apple software (if everyting works dandy, why the need for 'Force Quit' menu? Something tells me it's the same thing as Ctrl Alt- Del in Windows). Also, noticing that Apple's compose of only 3% of all computers, these flaws aren't noticed, but if apple get bigger, then we'll see the same thing as Microsoft--someone somewhere will find security holes in apples too.
Posted by Buckeroo (20 comments )
Reply Link Flag
More Detail Please?
Any info/links to these Mac viruses? I'm curious about their name/behavior etc. Thanks.

In response to your question...

Force Quit lets the user stop a "locked" application that is no longer responding to normal user inputs. Kind of like "End Task" in Windows.
Posted by open-mind (1027 comments )
Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Apple (1.86%) 9.18 502.60
Dow Jones Industrials (0.57%) 72.81 12,874.04
S&P 500 (0.68%) 9.13 1,351.77
NASDAQ (0.95%) 27.51 2,931.39
CNET TECH (0.84%) 17.13 2,049.14
  Symbol Lookup