Friday, January 11th 2008
Zero-Day Exploit for Apple QuickTime Posted
An Italian security researcher has posted a proof-of-concept exploit for a zero-day vulnerability in the most current version of Apple's QuickTime media software (7.3.1) which affects both Windows and Mac OS X. According to Luigi Auriemma the bug is a buffer-overflow which happens during the handling of the HTTP error message and its visualization in the LCD-like screen which contains info about the status of the connection. Buffer overflows can often be exploited by attackers to compromise the affected system. In this scenario, that's exactly what this bug can do. It can allow the attacker to take control the affected system. The vulnerability Auriemma has identified has no fix at the moment, so keep it in mind if you use the latest QuickTime on your system. Find out more about the exploit here.
Source:
News! Yahoo
8 Comments on Zero-Day Exploit for Apple QuickTime Posted
h**p://www.codecguide.com/about_qt.htm
:roll::roll::roll: