Apple Fixes First Flaw From 'Month Of Apple Bugs' - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
Software // Enterprise Applications
News
1/24/2007
02:28 PM
50%
50%

Apple Fixes First Flaw From 'Month Of Apple Bugs'

The patch comes 23 days after the researcher known only as "LMH" posted the flaw and proof-of-concept code as the opening round of his month of bugs.

Apple has patched the QuickTime vulnerability that was featured as the debut flaw in a researcher's ongoing Month of Apple Bugs project, a month-long campaign to spotlight problems in Apple's Mac OS X and applications.

The patch comes 23 days after the researcher known only as "LMH" posted the flaw and proof-of-concept code as the opening round of his month of bugs. The vulnerability is in QuickTime 7's parsing of RTSP (RealTime Streaming Protocol), a protocol used to transmit streaming audio, video, and 3-D animation over the Web. Users duped into clicking on an overlong rtsp:// link could have their PCs or Macs completely compromised, possibly automatically as soon as their browser reaches the site.

Apple's update adds validation of RTSP URLs, the Cupertino, Calif., computer and software maker said in the online advisory that accompanied the patch.

A day after LMH unveiled the QuickTime flaw, a Mac developer posted his own patch as part of a response to the bug-a-day project. Landon Fuller, who works on the DarwinPorts project, said he stepped in as "part brain exercise, part public service." So far, he and other researchers have published fixes for 20 of the 23 bugs listed on the Month of Apple Bugs site. Earlier this month, Apple declined to confirm any of the Month of Apple Bugs vulnerabilities and only issued a standard statement saying, "Apple takes security very seriously and has a great track record of addressing potential vulnerabilities before they can affect users. We always welcome feedback on how to improve security on the Mac."

The patches for QuickTime 7.1.3 for Mac OS X 10.4 (Tiger) and 10.3 (Panther) are available as separate downloads, but the Windows fix -- that edition of the media player also is flawed -- requires the use of Software Update, an optional component of the combined Windows QuickTime/iTunes download.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
News
How to Create a Successful AI Program
Jessica Davis, Senior Editor, Enterprise Apps,  10/14/2020
News
Think Like a Chief Innovation Officer and Get Work Done
Joao-Pierre S. Ruth, Senior Writer,  10/13/2020
Slideshows
10 Trends Accelerating Edge Computing
Cynthia Harvey, Freelance Journalist, InformationWeek,  10/8/2020
White Papers
Register for InformationWeek Newsletters
Video
Current Issue
[Special Report] Edge Computing: An IT Platform for the New Enterprise
Edge computing is poised to make a major splash within the next generation of corporate IT architectures. Here's what you need to know!
Slideshows
Flash Poll