MALWARE

Apple Bug-Tracking Project Releases QuickTime Exploit

Print Version
E-Mail Article
Reprints

The new Month of Apple Bugs Web site on Tuesday highlighted a zero-day Apple QuickTime flaw for Mac OS X and Windows systems in Quicktime's "rtsp:// URL" handler. By supplying a specially crafted string of HTML code, JavaScript, or a QTL file as an attack vector, a hacker could exploit the vulnerability to execute code on a victim's computer remotely.


Rackspace is the expert when it comes to delivering hosting solutions. From building out Windows and Linux servers and highly complex configurations to managing and supporting network environments, mail solutions, storage, data backups and far more, Rackspace is here to make your life easier. Learn more.

Remember the Month of Browser Bugs and the Month of Kernel Bugs? Apple (Nasdaq: AAPL) Latest News about Apple has now been singled out for the latest vulnerability project.

Security researchers are reviewing the first flaw in what is being dubbed the "Month of Apple Bugs" (MOAB), a project designed to improve the Mac by uncovering security flaws in Apple software and third-party applications developed for Mac OS X. The project aims to release a new vulnerability each day during the month of January.

As with its 2006 predecessors that targeted browsers and kernels, the Month of Apple Bugs project is expected to identify a new vulnerability each day during the month of January. The project kicked off Tuesday by exposing a simple vulnerability in Apple's QuickTime Latest News about QuickTime application, a program that allows users to capture, watch and share videos with friends.

The First Vulnerability

The vulnerability exists in Quicktime's "rtsp:// URL" handler. By supplying a specially crafted string of HTML code, JavaScript, or a QTL file as an attack vector, a hacker could exploit the vulnerability to execute code on a victim's computer remotely.

The issue has been successfully exploited in QuickTime Version 7.1.3, accord to the MOAB Web site. Previous versions should be vulnerable as well, according to MOAB project leaders. Both Windows Rackspace is the expert when it comes to delivering Windows and Linux hosting solutions. Click here to learn more. and Mac OS X versions are affected. Project leaders described the vulnerability as "trivial" to exploit and, as a demonstration, published code displaying "Happy New Year" on systems running QuickTime.

Apple could not immediately be reached for comment.

"Based on the first bug and earlier comments, it appears that working proof-of-concept exploit code will be released with at least some of the bugs. Given the lack of patches for these issues, these bugs could be used for targeted attacks of malicious code," said Michael Sutton, security evangelist at SPI Dynamics.

The project leaders deny that MOAB is intended as any kind of plot to discredit the computer maker. "Getting problems solved makes [using OS X] a bit more safe each day," they wrote on the MOAB Web site. "Flaws exist with and without people disclosing them. If we wanted to make [a] business out of this, we would be selling the issues and the proper exploit for each one."

No Advance Warning

Apple will not receive notification prior to the release of most advisories, they added, explaining, "the problem with so-called 'responsible disclosure' is that for some people, it means keeping others on hold for insane amounts of time -- even when the fix should be trivial."

In light of MOAB's intent, Sutton expects Apple will scramble to release some software patches.

Historically, Apple has not been the target of security researchers. "With its recent move to the Intel (Nasdaq: INTC) Latest News about Intel platform and increasing popularity, Apple should expect to come under greater scrutiny," Sutton concluded.

Social Networking Toolbox:

Print Version E-Mail Article Reprints More by Jennifer LeClaire   RSS

Related Resources

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]