Blogvaria

This page is brought to you by Blogvaria (http://blog.evaria.com).

To obtain more information, ask questions and interact please visit our website.

Back to Blogvaria landing page
Feedback
Subscribe
   
Blogvaria

 

The personal pages

QuickTime - no thanks

TrackBack | Filed by Wennichen under Software | Post popularity 7%

After 8 security fixes last year (according to Secunia) the Danish security company CSIS named Apple Quicktime as the biggest isolated security risk of 2007. Today Apple announces its third major fix this year.

The main 5 is listed below (source: Secunia):

  1. A boundary error when parsing packed scanlines from a PixData structure in a PICT file can be exploited to cause a heap-based buffer overflow via a specially crafted PICT file.
  2. An error in the processing of AAC-encoded media content can be exploited to cause a memory corruption via a specially crafted media file.
  3. A boundary error in the processing of PICT files can be exploited to cause a heap-based buffer overflow via a specially crafted PICT file.
  4. A boundary error in the processing of Indeo video codec content can be exploited to cause a stack-based buffer overflow via a specially crafted movie file with Indeo video codec content.
  5. An error in the handling of “file:” URLs can be exploited to e.g. execute arbitrary programs when playing specially crafted QuickTIme content in QuickTime Player.

As the “trend” seems to continue I’ll use alternative media players (as I’ve always done), and it appears you should do it too…

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • BlinkList
  • blogmarks
  • del.icio.us
  • De.lirio.us
  • digg
  • Furl
  • NewsVine
  • Netscape
  • Reddit
  • Spurl
  • SphereIt
  • Technorati
  • YahooMyWeb
  • DZone
  • feedmelinks
  • Linkter
  • Ma.gnolia
  • Slashdot
  • StumbleUpon
  • TailRank
  • co.mments

No comments yet.

Leave a Comment

Akismet has protected Blogvaria from 68,543 spam comments. Design by Evaria.com. Powered by WordPress.
Our beloved and trusted server has rendered 2.266 pages so far today, an amazing 3.891 pages yesterday
and even more astonishingly 105.402 pages since 13 August 2008 alone without dropping a byte nor a pixel.

Close
E-mail It