This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Month of Apple Bugs begins...

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.eweek.com/article2/0,1895,2078180,00.asp
January 1, 2007
"An easy-to-exploit security vulnerability in Apple Computer's QuickTime media player could put millions of Macintosh and Windows users at risk of code execution attacks. The QuickTime flaw kicked off the Month of Apple Bugs project, which promises to expose unpatched Mac OS X and Apple application vulnerabilities on a daily basis throughout the month of January…"

> http://secunia.com/advisories/23540/

:ph34r:
More…

- http://blog.washingtonpost.com/securityfix…ff_month_1.html
January 1, 2007
"…LMH said the Windows and Mac QuickTime Version 7.1.3 and the Player Version 7.1.3 are vulnerable, and that earlier versions also are likely to be vulnerable. QuickTime users can mitigate the threat from this bug by not opening links that begin with "rtsp://" or by disabling the display of streaming files in QuickTime.

To do that on a Mac, open QuickTime, go to "Preferences," then click on the "Advanced" tab. You should see a "Mime Settings" button; click on that, and then uncheck the box next to "Streaming - Streaming Movies."

For Windows users of the most current QuickTime version, click on "Edit," then 'Preferences," and then "QuickTime Preferences". Click on the "File Types" tab, and then on the plus sign next to "Streaming - Streaming Movies" and uncheck the box next to "RSTP stream descriptor"…"

Also see: http://isc.sans.org/diary.php?storyid=1993
Last Updated: 2007-01-02 00:54:21 UTC

(Screenshots available at the ISC URL above.)

:ph34r: ;)