By Jay Lyman MacNewsWorld Part of the ECT News Network
05/03/04 1:31 PM PT
Ken Dunham, iDefense director of malicious code research, said that there have been so few significant security issues with Apple's software that the company may have a point in holding back on an advisory.
Think you have to compromise on security to save on costs? Think Again. Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™, can lower your content security management costs by up to 40%. Find out just how much you’ll save with our TCO Impact Calculator.
Apple (Nasdaq: AAPL) is being criticized for its handling of a reported security vulnerability that -- although addressed in an updated version of the QuickTime media player -- was downplayed by the Cupertino, California-based company and denied security advisory status.
eEye Digital Security, a frequent finder of flaws in software from Microsoft (Nasdaq: MSFT), Apple and other leading vendors -- including Symantec (Nasdaq: SYMC) -- reported the QuickTime flaw as a critical vulnerability because it allows a remote attacker to overwrite heap memory with user-controlled data and execute arbitrary code, according to eEye's advisory.
eEye said the media player flaw was in the QuickTime .qts file that is used by many applications to access the media player and insisted it was not an issue that would simply crash the program. eEye said an attacker could use a movie file to trigger a direct heap overwrite, which would then allow execution of code.
"It is difficult to express just how textbook this vulnerability scenario really is," said eEye's advisory. "Successful exploitation of the vulnerability is self-evident, and therefore, no further discussion is warranted. It is our sincere hope that the vendor will make an earnest effort to increase the maturity of its security response capabilities, so that researchers will be encouraged to continue to work with them amicably on future security issues."
Confirmation Crucial
Apple is generally credited with strong security in its software and solid security response to vulnerability issues, which arise far more seldom than Microsoft Windows holes. However, independent security expert Ryan Russell agreed with eEye's call for an advisory on the latest issue.
"Most people won't update, and that's a danger," Russell told TechNewsWorld. "It's a big, long download and a lot of people would not normally undertake that update if they're not aware."
Russell, who praised Apple for its speed in responding to issues, said most companies that go through security problems arrive at a process that includes free reporting avenues and disclosure through advisories.
"I believe that most companies that have a security issue with their software should issue an advisory just to confirm there is a problem," Russell said, adding that notification should be accompanied by prompt patching and confrontation of the vulnerability in future iterations.
Ripeness of Apple's Security
In its advisory, eEye argued Apple "is doing a disservice to its customers by incorrectly labeling this vulnerability as a 'crash bug' rather than stating correctly that attackers can compromise systems running the affected Apple software."
Russell referred to Apple's support of fixes for newer versions of its software that have been known to leave out older versions and said the latest Apple security response may highlight the company's limited security experience.
"This hints that there is a real lack of maturity, or inexperience may be a better way to put it, with their response," Russell said. "Most companies have arrived at that process [of releasing advisories]. Apple, I believe, will arrive there with a little more experience."
Reasons To Hold Off
Ken Dunham, iDefense director of malicious code research, said that there have been so few significant security issues with Apple's software that the company may have a point in holding back on an advisory.
"The fact that they have not had to deal with as large of a problem or as high of a level problem does lend credibility in saying the likelihood of attack is lower," Dunham told TechNewsWorld. "Right now, there's a benefit to not sending out such advisories, which might lend importance or risk.
"If they don't really need to send one out, they might not want to, and they may not need to in this case," Dunham added. "Because it's so rare and so unlikely compared to all of the other threats that are out there, it's a totally different environment."
If it is true that Apple has no interest in selling computers to the enterprise, why did they ...
Next Article in Security
Sasser Worm Poses New Security Threats May 03, 2004
"These are two separate but unique working exploits," Charles Kaplan, MSS information security officer at VeriSign, told TechNewsWorld. "The LSASS exploit is far more significant because it will impact all unprotected PCs."
Related Stories
Mac OS X Attacked by Trojan Horse April 09, 2004
Forrester analyst Jan Sundgren told TechNewsWorld that with far fewer vulnerabilities and viruses than Windows, Mac users could be in danger with their guard down. However, Sundgren downplayed the threat of MP3Virus.Gen, adding that Mac OS X is not nearly as popular of a target for attackers who are looking to get an "explosive outbreak."
RealNetworks Warns of Remote Attack Danger April 08, 2004
Aberdeen Group vice president Jim Hurley said it is extremely difficult for media player vendors to test the security of their products on all of the various platforms on which they run. "It's almost impossible for one supplier to test all of the outcomes of how their products can be hacked," Hurley told TechNewsWorld.
Apple Ships First Xserve G5s, Unveils Workgroup Clusters March 23, 2004
In general, commercial data centers are less inclined to change their existing setups and vendor agreements than research centers, Haff said, which may be one reason why Apple is having more success in the research space. However, members of the scientific community tend to be fickle buyers, which puts a great deal of pressure on Apple to keep up the performance of its server offerings, he added.
EU Moves To Sever Microsoft's Media Player from Windows March 08, 2004
"At a certain point, if you've backed Microsoft up against a wall, they will not back down," Yankee Group senior analyst Laura DiDio told TechNewsWorld. "They'll appeal, appeal, appeal. They're not going to turn their strategy for Media Player upside down for the European Commission."
RealNetworks Warns of Media Player Security Holes February 06, 2004
Aberdeen Group vice president Jim Hurley told TechNewsWorld that it is extremely difficult for media player vendors to test the security of their software on all the platforms on which they run. "It's almost impossible for one supplier to test all of the outcomes of how their products can be hacked," he said.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.