FEATURED VIDEO

Sponsored By:


SLIDE SHOWS
Manufacturers brought the industry radical new ways to build PCs in 2008. Here are some of the coolest components we came across in 2008.
From gaming to business, retail to commercial, Wi-Fi to WiMAX, 2008 was the most cutting-edge year ever in the history of mobile computing.
From iPhones to BlackBerrys, 2008 saw the emergence of touch-screen titans, the first LG smartphone to hit the U.S. and the first device based on Google Android. Here are the 10 coolest smartphones that hit the market in 2008.
INSIDE CHANNELWEB
techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Network Analyst
Hebrew Senior Life seeking Network Analyst in Dedham, MA
spacer

Month Of Apple Bugs Starts With QuickTime Exploit


CRN logo By Kevin McLaughlin, ChannelWeb
2:00 PM EST Tue. Jan. 02, 2007
The Month of Apple Bugs, a project that aims to post an Apple vulnerability per day during January, launched on New Year's Day with a remote code execution flaw in Apple's QuickTime media streaming software.

The vulnerability involves the way QuickTime handles URLs using the Real Time Streaming Protocol (RTSP), a standard for broadcasting multimedia content online. An attacker could enter a URL with a specially crafted text string to trigger a buffer overflow and open the door to malicious code execution, according to a Monday blog post by one of the co-organizers of the project, a security researcher who uses the handle L.M.H.

L.M.H. and his partner in the project, security researcher Kevin Finisterre, posted a working exploit for the flaw that has been tested on QuickTime Version 7.1.3. Previous versions "should be vulnerable as well," and the only potential workaround for the flaw would be to disable the RTSP URL handler, the researchers wrote.

Vendors that issue threat ratings were in agreement about the severity of the flaw. Secunia rated it "highly critical," or 4 on a 5-point scale. Symantec rated it 8.3 on a 10-point scale, and the French Security Incident Research Team (FrSIRT) rated it "critical," or 4 on a 4-point scale.

When asked about the QuickTime vulnerability, Apple spokesman Anuj Nayar said, "Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users. We always welcome feedback on how to improve security on the Mac."


RATE THIS ARTICLE Worse 1 2 3 4 5 Better
CHANNELWEB MARKETSPACE >> (Sponsored Links)
Channelweb : Promofinder
FEATURED PROMOTIONS
Weatherproof LCD Monitor
IP65 Weather/Waterproof/Outdoor LCD Monitor (LCD Display), Auto Power Saving, VESA Mounting, Sunlight Readable, Wide Temperat...
Partnerpedia Free Partner Portal
Partnerpedia is a free online community dedicated to helping companies expand their market reach through partnering. There’...
RELATED BLOG >>
Photo
Microsoft will only fix one Windows security error for its first Patch Tuesday of 2009.
ADVERTISEMENT




CHANNEL SERVICES >>