The Last HOPE
-->
         
         
Email us! Subscribe to Liquidmatrix!

Apple QuickTime Exploit In The Wild

There is a working exploit for Apple QuickTime on the loose.

From Secunia:

Description:
h07 has discovered a vulnerability in Apple QuickTime, which can be exploited by malicious people to compromise a user’s system.

The vulnerability is caused due to a boundary error when processing RTSP replies and can be exploited to cause a stack-based buffer overflow via a specially crafted RTSP reply containing an overly long “Content-Type” header.

Successful exploitation allows execution of arbitrary code and requires that the user is e.g. tricked into opening a malicious QTL file or visiting a malicious web site.

The vulnerability is confirmed in version 7.3. Other versions may also be affected.

NOTE: A working exploit is publicly available.

Advisory Link

Exploit Link

Tags: , ,

Tag It: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • Apple Fixes Serious QuickTime Bug
  • Apple Security Update For May 1st
  • QuickTime Multiple Vulnerabilities (Fire Bad)
  • Swarm of QuickTime Bugs Found
  • Apple QuickTime Java Handling Unspecified Code Execution
  • Leave a Comment