All the latest UK technology news, reviews and analysis

Apple QuickTime hit by buffer overflow

by Matt Chapman

02 Jan 2007

Be the first to comment

  • Tweet this
Apple QuickTime
The latest QuickTime flaw affects Windows and Mac systems

Apple's QuickTime software has been hit by a buffer overflow bug that could allow malicious code to be run on Windows and Mac PCs. 

The vulnerability uses a specially crafted QTL file to cause a stack-based buffer overflow that allows the execution of arbitrary code.

The problem occurs when an 'src' parameter is created with more than 256 bytes.

"After successful exploitation, control over EIP is gained. This is a simple good-old stack smashing," said the first report of the problem at the Month of Apple Bugs website. 

The vulnerability has been successfully exploited in QuickTime version 7.1.3, although previous versions are also expected to be vulnerable.

Security website Secunia warned that the only way for users to protect themselves against the attack is not to open untrusted QTL files.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Dynamics AX/AXAPTA Functional Consultant, 55k! Home working!

My multi- national Partner client has charged me exclusively...

Senior IT Operations Engineer -MCSE, IIS7/7.5, SAN, CDN

Senior IT Operations Engineer -MCSE, IIS7/7.5, SAN, CDN...

Bitlocker Consultant

I have an urgent requirement for short term contract...

User Interface Developer x 1/2 - South West

User Interface Developer x 1/2 - Leading Organisation...

To send to more than one email address, simply separate each address with a comma.