image
image

Go Back   macosx.com > Content & Information > Apple News, Rumors & Discussion

Reply
 
Thread Tools
  #1  
Old January 4th, 2007, 04:54 AM
Sunnz's Avatar
Who wants a stylus?
 
Join Date: Nov 2005
Location: Canberra, Australia
Posts: 359
Thanks: 0
Thanked 0 Times in 0 Posts
Sunnz is on a distinguished road
Vulnerabilities within QuickTime?

On a FreeBSD mailing list, someone quoted Apple:
Quote:
The Apple Security Team reports that there are multiple
vulnerabilities within QuickTime (one of the plugins for
win32-codecs). A remote attacker capable of creating a malicious SGI
image, FlashPix, FLC movie, or a QuickTime movie can possibly lead to
execution of arbitrary code or cause a Denial of Service (application
crash).

Users who have QuickTime (/win32-codecs) as a browser plugin may be
vulnerable to remote code execution by visiting a website containing a
malicious SGI image, FlashPix, FLC movie or a QuickTime movie.
Of course, they are most concerned with win32codecs on their OS...

So, what about OSX? Do we have this vulnerability in the pre-installed quicktime as well? Did Apple really announced this? Does anyone know if there is an official Apple Security Advisory list?
__________________
[SIGPIC][/SIGPIC]

Catel - Core 2 Duo 2.0Ghz, 1GB Ram, OSX Tiger.8

AMDemon - Dual Opteron 2.6Ghz, 2GB Ram, FreeBSD 6.1
Reply With Quote
  #2  
Old January 4th, 2007, 04:59 AM
fryke's Avatar
Super Moderator
 
Join Date: Sep 2000
Location: macosx.com
Posts: 13,156
Thanks: 2
Thanked 12 Times in 12 Posts
fryke has a spectacular aura aboutfryke has a spectacular aura about
I'm not sure about this particular bug, but January 2007 _is_ "month of apple bugs" here -> http://projects.info-pull.com/moab/ ... Should be interesting.

Apple _does_ release information and security updates on this page: http://docs.info.apple.com/article.html?artnum=61798 ... There are links to updates and descriptions etc., although this, of course, only gets released when an update is available as well.
__________________
MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.5.5
MacBook 13" 1.83 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
Hackintosh Core2Duo 2.4 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
iPhone 3G 16 GB (v2.1), AppleTV 1G 40 GB (v2.1)

Mac user since 1987, Apple Product Professional 2007, 2008.
Reply With Quote
  #3  
Old January 4th, 2007, 05:24 AM
Sunnz's Avatar
Who wants a stylus?
 
Join Date: Nov 2005
Location: Canberra, Australia
Posts: 359
Thanks: 0
Thanked 0 Times in 0 Posts
Sunnz is on a distinguished road
Hmm... aren't they the same people who "proved" MacBook's wireless vulnerability... not using the internal Airport but a 3rd party wifi card?
__________________
[SIGPIC][/SIGPIC]

Catel - Core 2 Duo 2.0Ghz, 1GB Ram, OSX Tiger.8

AMDemon - Dual Opteron 2.6Ghz, 2GB Ram, FreeBSD 6.1
Reply With Quote
  #4  
Old January 4th, 2007, 06:00 AM
Sunnz's Avatar
Who wants a stylus?
 
Join Date: Nov 2005
Location: Canberra, Australia
Posts: 359
Thanks: 0
Thanked 0 Times in 0 Posts
Sunnz is on a distinguished road
Anyway, found a link about QT 7.1.3 from Apple: http://docs.info.apple.com/article.html?artnum=304357
__________________
[SIGPIC][/SIGPIC]

Catel - Core 2 Duo 2.0Ghz, 1GB Ram, OSX Tiger.8

AMDemon - Dual Opteron 2.6Ghz, 2GB Ram, FreeBSD 6.1
Reply With Quote
  #5  
Old January 4th, 2007, 06:20 AM
fryke's Avatar
Super Moderator
 
Join Date: Sep 2000
Location: macosx.com
Posts: 13,156
Thanks: 2
Thanked 12 Times in 12 Posts
fryke has a spectacular aura aboutfryke has a spectacular aura about
Even _if_ those are the same guys, doesn't make the bugs go away. I really hope Apple uses this "MOAB" thing for their own good, fixing things promptly and responding in a timely fashion.
So far, they've only kinda "welcomed" the MOAB. But nothing more about it.
__________________
MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.5.5
MacBook 13" 1.83 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
Hackintosh Core2Duo 2.4 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
iPhone 3G 16 GB (v2.1), AppleTV 1G 40 GB (v2.1)

Mac user since 1987, Apple Product Professional 2007, 2008.
Reply With Quote
  #6  
Old January 4th, 2007, 09:05 AM
Sunnz's Avatar
Who wants a stylus?
 
Join Date: Nov 2005
Location: Canberra, Australia
Posts: 359
Thanks: 0
Thanked 0 Times in 0 Posts
Sunnz is on a distinguished road
Well, guess what? Landon Fuller, a programmer, Darwin developer, and former engineer in Apple's BSD Technology Group, comes to rescue!!!

http://landonf.bikemonkey.org/code/macosx

Basically he's gotta to squat each MOAB as they are released.
__________________
[SIGPIC][/SIGPIC]

Catel - Core 2 Duo 2.0Ghz, 1GB Ram, OSX Tiger.8

AMDemon - Dual Opteron 2.6Ghz, 2GB Ram, FreeBSD 6.1
Reply With Quote
  #7  
Old January 4th, 2007, 02:32 PM
fryke's Avatar
Super Moderator
 
Join Date: Sep 2000
Location: macosx.com
Posts: 13,156
Thanks: 2
Thanked 12 Times in 12 Posts
fryke has a spectacular aura aboutfryke has a spectacular aura about
nice. ... although i _still_ hope that Apple will answer the MOAB appropriately. Maybe they can simply take the fixes and implement them, so they can release one security update at the end of the month.
__________________
MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.5.5
MacBook 13" 1.83 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
Hackintosh Core2Duo 2.4 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
iPhone 3G 16 GB (v2.1), AppleTV 1G 40 GB (v2.1)

Mac user since 1987, Apple Product Professional 2007, 2008.
Reply With Quote
  #8  
Old January 4th, 2007, 07:24 PM
lurk's Avatar
Mitä?
 
Join Date: Mar 2002
Location: Land o' skeeterz
Posts: 2,076
Thanks: 0
Thanked 0 Times in 0 Posts
lurk is on a distinguished road
I wonder about the ground rules on this though, Day 2 was a bug in VLC that is not really an Apple bug is it? I mean if that is the case we could fill up the rest of the month with Word alone ;-)

// Computer brand loyalty is teh kewl!
__________________
Wenn ist das Nunstruck git und Slotermeyer? Ja!...
Beiherhund das Oder die Flipperwaldt gersput!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 10:53 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.