Filed under: Multimedia, iTunes, Security
Zero-day exploit for QuickTime in the wild
A hacker who found a vulnerability in QuickTime said he posted the attack code online after Apple ignored him for a month.
The code exploits a flaw in QuickTime that causes a crash when a unusually-long parameter is passed along with a movie file. While it's not demonstrated, the hacker claims that "code execution may be possible."
With Leopard, address space randomization makes it more difficult to execute code in memory spaces left after a crash. Earlier operating systems (like Tiger and Panther) may still be vulnerable.
Apple hasn't released any guidelines to avoid the problem, as it does in high-risk cases. Intego, in a press release, considered the risk "low" and will be updating its VirusBarrier X5 software if someone creates malicious software based on the attack technique.
Even though the risk may be low, an abundance of caution is always advised. Be careful when opening (or clicking links to) QuickTime files from sources unknown to you. In the past, phishing/malware attacks have been delivered as fake QuickTime or Windows Media codecs, so remember that any executable file you download from an unfamiliar source may be suspect.
[Via InformationWeek and IDG.]

![TUAW [Cafepress]](http://www.blogsmithmedia.com/www.tuaw.com/media/tuaw-cafepress-promo.png)


Reader Comments (Page 1 of 1)
alansky said 1:34PM on 9-18-2008
Curiosity killed the cat!
When will people learn not to open unknown downloads, not to click links embedded in email messages... This is not exactly rocket science!
Reply
SpinThis! said 2:34PM on 9-18-2008
"Code execution may be possible." Oh really? You know, if you want to get Apple's attention, get some code to execute otherwise it's just another browser crash. Apple is either not taking this seriously or more likely, they've looked into this and considered it's not really a serious threat and it's on the bug-fix list.
It's amazing the number of anti-Apple people who sneak out of the woodwork every time some hacker finds a little bug—no matter how severe—and spouts FUD about how insecure Mac OS X or how it'll become the virus-laden minefield that Windows is if the user base ever grows.
Some concern is definitely merited, especially with the already released open source software Apple bundles with the OS. In some aspects Apple is a couple versions behind what the latest point release is and usually all it takes is a recompile to get up-to-date. I agree with the article—Apple could take security a little more seriously but this is hardly front-page news.
Reply
Jesse said 12:19AM on 9-19-2008
Actually, Address Space Layout Randomization (ASLR) was never fully implemented in Leopard. So little of it was, that it may as well not be in there at all.
I was rather disappointed to learn of this, after the promises by Apple.
The Matasano blog posted some technical details about a year ago:
http://www.matasano.com/log/986/what-weve-since-learned-about-leopard-security-features/
(Numerous others have corroborated the findings, but that was the first link I had handy)
It's time to end the delusions of OSX security. I love the OS, but Apple has been very lucky in that it's avoided scrutiny for this long. There are plenty of technologies available, and there's no reason that they can't spend a little money on this before it really becomes a target. Every other OS has gone through it, and ours will be no different.
Reply
Paul said 11:22AM on 9-19-2008
Wait, a multi-billion dollar company doesn't answer every little e-mail it gets, and so the responsible thing to do is get huffy and post damaging information that could potentially inconvenience millions of people?
Smooth. Ethical. Mature. Jerk.
Reply