|
25 November 2007 18:41 by Rich "vurbal" Fiscus
| 12 comments
Security analysts are warning that a bug in Apple's QuickTime threatens to allow hackers to install malware on computers running Windows XP or Vista or even get a list of passwords from the target computer.
According to Symantec analyst Anthony Roe, the flaw is more easily exploited in Vista than it would be under normal circumstances because Apple developers failed to take advantage of a Vista feature called Address Space Layout Randomization (ASLR). ASLR allows Windows Vista to load binaries (like quicktime) into memory in random locations, making it harder for an attacker to identify a particualar piece of code among all the other data stored in memory.
Another Symantec researcher, Patrick Jungles, added that QuickTime vulnerabilities usually draw attackers quickly. "In the past, we have seen a very short period of time between the release of proof-of-concept exploits for QuickTime vulnerabilities and the development of working exploits by attackers," said Jungles in a note to customers of his company's DeepSight threat network. "Popular applications such as QuickTime are strong candidates for exploitation in the wild."
Source: Computerworld
Permalink to this article
| |
Related articles:
Apple fixes QuickTime security problems (6 April 2008)
Apple patches security flaws in iPhone, QuickTime (16 January 2008)
Patch available for SafeDisc security flaw (6 November 2007)
iPhone criticized by security community (23 October 2007)
Real to offer fix for RealPlayer security flaw (20 October 2007)
Apple patches Windows Quicktime flaw (4 October 2007)
Malware authors target video revolution (2 October 2007)
|
|
|
| Discuss this article! |
| furchtlos (Newbie) 25 November 2007 20:48 |
|
|
better be careful then.
|
| duckNrun (Member) 25 November 2007 20:58 |
|
|
$10 says that the fanboys will be saying this is a MS issue and St Jobs' code is as pure as snow and can't be faulted
|
| mediabob (Member) 25 November 2007 23:10 |
|
its a conspiracy! apple wants the hackers to destroy xp and vista!!!!!!!!!! hahahah. im completely impartial between windows and os x. i thought itd be funny
|
| duckNrun (Member) 26 November 2007 3:01 |
|
Originally posted by mediabob: its a conspiracy! apple wants the hackers to destroy xp and vista!!!!!!!!!! hahahah. im completely impartial between windows and os x. i thought itd be funny
lol
I use what I use because I use it, which btw is XP. I have looked at and considered Linux on my next PC for all my 'on the web' usuage for security and whatnot. Of course I would still be windows native for my gaming.
That being said I have never had a problem with XP being malware or virus infested. The few times I did catch something was due to my own actions while I was 'off roading' on the net.
If I could grab a copy of Tiger or Leopard or whatever it is now I would gladly give it a spin and if I liked it I would probably keep it. I'm just not willing to 'upgrade' my system to the Jobs Mob
|
| ali2007 (Inactive) 26 November 2007 6:42 |
|
i usually use comodo firewall on xp and vista which usually keeps me off malware and viruses and connects to only website i want to connect.
highly recommened people to use it
|
| ali2007 (Inactive) 26 November 2007 6:46 |
|
i usually use comodo firewall on xp and vista which usually keeps me off malware and viruses and connects to only website i want to connect.
highly recommened people to use it
|
| xSModder (Junior Member) 26 November 2007 10:44 |
|
|
Does anybody really even use Quicktime anymore?
I mean, come on guys, Windows 98 is not gonna cut it forever.
|
| emugamer (Member) 26 November 2007 11:46 |
|
Originally posted by xSModder: Does anybody really even use Quicktime anymore?
I mean, come on guys, Windows 98 is not gonna cut it forever.
Yes, there are current XP apps that require the user to install the latest Quicktime. The Total Training series for example. I use their Advanced Photoshop and Illustrator training. That's just 1 example. I'm sure other members can think of a few more.
|
| xSModder (Junior Member) 26 November 2007 13:09 |
|
You know, there are quicktime alternatives. I mean, sure, the codec is still used, but there are other players and such. And if it comes integrated or bundled, I'd say it's likely a piece of crap and they're just trying to get it out there.
Do people really get Quicktime PRO?
I mean, why bother spending even 5 dollars, let alone a 1 minute download?
It's just dumb in my opinion.
And for the programs that require this ungodly add-on...I think it's time they make the switch.
|
| emugamer (Member) 27 November 2007 6:31 |
|
Originally posted by xSModder: You know, there are quicktime alternatives. I mean, sure, the codec is still used, but there are other players and such. And if it comes integrated or bundled, I'd say it's likely a piece of crap and they're just trying to get it out there.
Do people really get Quicktime PRO?
I mean, why bother spending even 5 dollars, let alone a 1 minute download?
It's just dumb in my opinion.
And for the programs that require this ungodly add-on...I think it's time they make the switch.
Yeah, I wish Total Training would use something else. I wouldn't pay for Quicktime as a standalone app. It's unfortunate that I have it on my PC. But I haven't found any training series as good as theirs.
|
| Mez (Senior Member) 30 November 2007 7:29 |
|
A news flash for xSModder...
If you have iTunes installed on your PC you have QT running. Because QT is a memory hog and takes so long to load, Apple loads QT at startup! That is Apples solution to crappy software. Apple doesn't care if you never use it or can't use it becase your iPod can not play videos. They figure you are too stupid to figure it out where your memory got to. I guess it works for 99.9% of the population.
This message has been edited since posting. Last time this message was edited on 30 November 2007 7:34
|
| borhan9 (AfterDawn Addict) 20 December 2007 6:30 |
|
|
Well would it not be better to get rid of the software all together if this is the case every couple of months or every year wats going on.
|
|
|
Latest newsLatest news from AfterDawn.com. Denon introduces ‘Universal’ Blu-ray player 5 Dec, 2008 | 2 comments MPA wants London a ‘Fake-Free Zone’ before Olympics 4 Dec, 2008 | 3 comments YouTube to restrict sexually suggestive content 4 Dec, 2008 $99 4GB iPhone coming to Wal-Mart? 4 Dec, 2008 | 3 comments 'Dark Knight' becomes best selling movie of 2008, on iTunes 4 Dec, 2008 | 1 comment MySpace testing mobile video streaming service 4 Dec, 2008 Amazon MP3 store opens in UK 4 Dec, 2008 Pioneer 400GB Blu-ray discs will play on PS3 4 Dec, 2008 | 17 comments PS3 firmware update adds full screen flash viewing 4 Dec, 2008 | 5 comments Digital music sales to increase heavily by 2013, says firm 3 Dec, 2008 | 4 comments Xbox 360 outsells PS3 3-to-1 on Black Friday 3 Dec, 2008 | 39 comments RIAA sues hospitalized teen 2 Dec, 2008 | 34 comments
More news... 
Search for headlinesSearch through our news archive. 
Latest threadsRecently updated discussion threads. More... 
Last week's most popular software downloads
Most popular devicesLast week's most popular products in our product comparison service. More products... 
Top linksMost popular links - Blasteroids.com
Download game trailers, demos and more - TorrentReactor.Net
The most active torrents on the web - Digital-Digest
Latest DivX, XviD, DVD, Blu-Ray, HD DVD News - OpenSubtitles.org
download DivX subtitles from the biggest open database - CDRInfo.com
The Hardware Authority - DVDHelp.us
DVD help, tutorials, FAQ, and very popular free help forum! - Torrentreactor.TO
The most active torrents on the web - Ease Audio Converter.
Convert files from MP3, WAV, WMA, OGG, AAC, APE, FLAC, and MP4 to WAV and backwards.

|