![]() |
|
|||||||
| News Discuss QuickTime 'Extremely Critical' security flaw revealed...Security researchers have warned that attack code which targets an unpatched bug in Apple Inc.'s QuickTime is in the public ... |
|
Welcome to the Pixalo Photography Community. As a Guest you are free to browse the site, but see what extras you get as a Member here.
|
|
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Pixalo Crew
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 16,473
![]() ![]() ![]() |
QuickTime 'Extremely Critical' security flaw revealed
Security researchers have warned that attack code which targets an unpatched bug in Apple Inc.'s QuickTime is in the public domain; in-the-wild attacks against systems running Windows XP and Vista and possibly Mac OSX are probably being prepared by malicious hacker groups.
The critical bug in QuickTime 7.2 and 7.3 (and perhaps earlier editions as well) is in the player's handling of the Real Time Streaming Protocol (RTSP), an audio/video streaming standard. It is rated by Secunia as ' Extremely Critical'. The vulnerability is confirmed in version 7.3 of QuickTIme. Other versions may also be affected. According to alerts posted by Symantec Corp. and the U.S. Computer Emergency Readiness Team (US-CERT), attackers can exploit the flaw by duping users into visiting malicious or compromised Web sites hosting specially-crafted streaming content, or by convincing them to open a rigged QTL file attached to an e-mail message. A successful exploit would let the attacker install additional Malware -- spyware or a spambot, say -- or cull the system for information like passwords. An attack that failed would likely only crash QuickTime on Windows and Mac OSX systems. It appears from reports that Firefox is especially susceptible to this exploit, Internet Explorer and Safari browsers less so. Be cautious and only accept streaming video from known safe websites.
__________________
.......__o .......\<, ....( )/ ( ) |
|
|
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Highly Critical Adobe Reader security vulnerability | Steve | Computer hardware, software, networking and internet | 9 | 04-01-2007 15:37 |
| Microsoft Office has "extremely critical" hole | orangepeel | Computer hardware, software, networking and internet | 8 | 15-12-2006 13:54 |
| Extremely critical exploit in active X controls in IE6 and IE7 | Steve | Computer hardware, software, networking and internet | 0 | 05-11-2006 20:52 |
| Firefox 2 security gets critical attention | Steve | Computer hardware, software, networking and internet | 0 | 04-11-2006 09:43 |
| Another Critical security Flaw in Internet explorer | Steve | Computer hardware, software, networking and internet | 11 | 29-09-2006 15:02 |