NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


QuickTime Makes Vista More Vulnerable

More security flaws discovered in the application

By Bogdan Popa, Security and Search Engines Editor

6th of March 2007, 10:44 GMT

Adjust text size:


QuickTime is regarded as one of the most popular multimedia players on the market, being developed by Apple and available on multiple platforms including Mac, Linux and Windows. Although some users might think that a multimedia player is completely secure, Apple released a security advisory to announce 8 vulnerabilities in the QuickTime player. All the security flaws were confirmed in the old versions of the applications, being addressed to Windows, Linux and Mac platforms.

"An integer overflow
exists in QuickTime's handling of 3GP video files. By enticing a user to open a malicious movie, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of 3GP video files. This issue does not affect Mac OS X. Credit to JJ Reyes for reporting this issue," Apple sustained in the first security advisory for Windows 2000, XP and Vista.

"A heap buffer overflow exists in QuickTime's handling of MIDI files. By enticing a user to open a malicious MIDI file, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of MIDI files. Credit to Mike Price of McAfee AVERT Labs for reporting this issue," the company added.

The exploitation of the issue is quite simple: the attacker creates a malicious 3gp file that is distributed via email, file sharing application or other ways for file distribution. Once the user opens the movie, his computer can be controlled by the hacker using a simple remote connection.

The only solution presented by Apple is to update to the latest version of the application, currently 7.1.5. If you want to install the latest version of QuickTime for Windows, you can download it from Softpedia.

TAGS:

quicktime | windows | security | flaw | vulnerability
Read by 5,269 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Very Good (4.1/5) 9 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Apple Released iTunes and QuickTime Updates

iTunes and QuickTime Will Be Updated Soon

QuickTime Has Been Patched

QuickTime Got an Emmy

Need an iTunes Alternative?

Apple QuickTime Is Vulnerable to Attacks

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM