Home › News › Industry News
Vulnerability discovered in QuickTime
A new vulnerability has been discovered in QuickTime, this one affecting even the most updated version of Apple's software. An independent security researcher posted proof-of-concept for the newly discovered flaw, which is present in both the Windows and Mac OS X builds.
The flaw is a result of how QuickTime handles invalid RTSP links. QuickTime will attempt to load a stream, and if it is unable, tries to load the same stream on the standard HTTP port - and the server may feed the client too much data and cause it to overflow. While so far nothing more than crashing the software has been proven, it is possible the flaw could lead to code execution. There's no word from Apple if they are working on a fix.
The flaw is a result of how QuickTime handles invalid RTSP links. QuickTime will attempt to load a stream, and if it is unable, tries to load the same stream on the standard HTTP port - and the server may feed the client too much data and cause it to overflow. While so far nothing more than crashing the software has been proven, it is possible the flaw could lead to code execution. There's no word from Apple if they are working on a fix.
Related Stories
Most Popular
| Trending | Featured |
-
iOS 5.1.1 untethered jailbreak tool released, supports 4S, iPad 3
-
After five days, Facebook ranks as worst IPO flop of the decade
-
Rumor: Windows 8 RC will launch June 1, will ship with Adobe Flash
-
Rumor: AMD "Piledriver" FX CPU production to begin Q3 2012
-
Diablo III becomes the fastest-selling PC game in history
Editors' CPU Picks
Subscribe to TechSpot
Get free exclusive content, learn about new features and tech breaking news.