User User name Password  
   
Monday 9.11.2009 / 04:04 AM
Search AfterDawn.com:        In English   Suomeksi   På svenska
afterdawn.com > news > quicktime suffers another rtsp flaw
Show topics
News
News

QuickTime suffers another RTSP flaw

11 January 2008 18:34 by James "Dela" Delahunty | 2 comments

QuickTime suffers another RTSP flaw Yet another security flaw in how Apple's QuickTime software handles the Real Time Streaming Protocol (RTSP) has been revealed. If exploited by a malicious user, it is possible to run arbitrary code on a victim's computer. This flaw affects fully patched QuickTime version 7.3.1, running on Windows and possibly Mac OS X. It bares some resemblance to the QuickTime RTSP flaw reported in December.

Discovery of the latest flaw is credited to Luigi Auriemma, who has posted a concept exploit on his site. "For exploiting this vulnerability is only needed that an user follows a rtsp:// link, if the port 554 of the server is closed QuickTime will automatically change the transport and will try the HTTP protocol on port 80, the 404 error message of the server (other error numbers are valid too) will be visualized in the LCD-like screen," Auriemma wrote.

Source:
News.com


Permalink to this article

Get AfterDawn's news to your favourite feed reader! Share this story with your friends!
 

 
Related articles:

  • Apple to add YouTube support to QuickTime (29 April 2009)
  • Quicktime Pro going free? (10 February 2009)
  • Apple releases Quicktime update (22 January 2009)
  • Apple fixes QuickTime security problems (6 April 2008)
  • Apple patches security flaws in iPhone, QuickTime (16 January 2008)
  • Apple patches flaw in QuickTime software (24 January 2007)
  • New Quicktime vulnerability allows malicious attack (2 January 2007)
  •  

    « Previous news article
    CES 2008: HP's MediaSmart Receiver connects HDTVs wirelessly to network
    Next news article »
    Hauppauge shows its 'HD PVR'
     Post your comment
    Discuss this article! 
    tatsh (Junior Member) 11 January 2008 21:17 Send private message to this user   
    glad I use Linux :)
    ffmpeg and VLC both render QuickTime fine it seems, even RTSP in Firefox with mozplugger/mplayer.
    borhan9 (AfterDawn Addict) 23 January 2008 17:04 Send private message to this user   
    I may really need to update my quicktime and itunes software.
     Post your comment
     

    Subscribe to our newsfeed

    Get the latest headlines delivered directly to your favourite RSS reader or content aggregation service by using the links below.

    AfterDawn.com: News - RSS feed
    Add to Google
    Add to My Yahoo!
    Add to MyMSN

    Search for headlines

    Search through our news archive.

    Last week's most popular software downloads

    Digital video: AfterDawn.com | AfterDawn Forums
    Music: MP3Lizard.com
    Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
    Software: Software downloads
    Blogs: User profile pages
    RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
    International: AfterDawn in Finnish | AfterDawn in Swedish | download.fi
    Navigate: Search | Site map
    About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
    Contact us: Send feedback | Contact our media sales team
     
      © 1999-2009 by AfterDawn Ltd.