Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
MP3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code
p2pnet - rss feed: http://p2pnet.net/p2p.rss | p2pnet celebrities: http://p2pnet.net/celeb.rss | Mobile? http://p2pnet.net/index-wml.php

iTunes, Quicktime, security flaws

p2p news / p2pnet: A heap overflow vulnerability exists for all current and prior versions of Apple iTunes and Quicktime for Mac OS X and Win32, says indie security researcher Tom Ferris.

It could allow an attacker to cause a crash, and or execute arbitrary code in the context of the user who executes the player, he states

How severe is the flaw? It’s bad, says Ferris – “think about how many ipods sold this year alone”.

He gives links two testcases for the vulnerability and says Apple has been notified.

http://www.security-protocols.com/poc/sp-x21-1.mov <(=-- this one crashes QuickTime
http://www.security-protocols.com/poc/sp-x21-2.mov <(=-- this one will crash iTunes and QuickTime

Ferris told eWeek he flagged the issue to Apple more than a month ago, “but only received a cursory confirmation that the bug was being investigated”.

Attackers can, “rig QuickTime movie files to trigger a denial-of-service crash that may lead to malicious code execution,” says the story.

Also See:
Tom Ferris - Apple QuickTime 7.0.3 & iTunes 6.0.1 Heap Overflow, December 20, 2005
eWeek - Beware of Strange iTunes/QuickTime Movies, December 21, 2005

HOME

6 Responses to “iTunes, Quicktime, security flaws”

  1. Reader's Write Says:

    With the first link, Firefox also crashed.

  2. Reader's Write Says:

    Macs DO NOT HAVE vulnerabilities. It’s a fact you can bank on.

  3. Reader's Write Says:

    riiiiiight ;P

  4. Reader's Write Says:

    I’m still trying to decide if the original “You’ve got it wrong…” post was serious or they are just trying to throw some gas on the fire. Pretty funny if they really believe it (in a blind loyalty fanboy sort of way). Actually pretty funny either way…

  5. Reader's Write Says:

    It’s a joke son. Laugh.

    Any platform has security problems if you have the electronic equivalent of an unlocked door.

    Identifying those doors, on the other hand, is sometimes very hard.

  6. Reader's Write Says:

    Hey, son…the laughs on you. Welcome to reality.

Leave a Reply

    Advertisments
Teksavvy