This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

QuickTime RTSP buffer overflow vuln

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

QuickTime RTSP buffer overflow
> http://www.kb.cert.org/vuls/id/442497
Last Updated: 01/02/2007
"…QuickTime may allow remote arbitrary code to be executed via a long src parameter in RTSP URL strings… since QuickTime is a component of Apple iTunes, iTunes installations are also affected by this vulnerability. We are aware of publicly available proof-of-concept code that exploits this vulnerability…"

- http://forums.tomcoyote.org/index.php?act=…st&p=341698


:ph34r:
FYI…

> http://www.kb.cert.org/vuls/id/442497
Last Updated: 01/23/2007 ~ "…Apple has issued an update to this issue. See Apple Security Update 2007-001. This update appears to apply only to systems running Mac OS X. It is -not- clear that an update for Windows systems is available as of 2007-01-23…"

:wtf:
FYI…

- http://www.kb.cert.org/vuls/id/442497
1.24.2007 ~ "Solution: Apply Update: This issue is addressed in Apple Security Update 2007-001…
An update for Microsoft Windows XP and 2000 systems is available via the Apple Software Update* application installed with QuickTime 7.1.3…"
(NOTE: See c:\program files\apple software update\softwareupdate.exe to start the program.)

How to repair Software Update for Windows
* http://docs.info.apple.com/article.html?artnum=304264

How to tell if Software Update for Windows is working correctly when no updates are available
- http://docs.info.apple.com/article.html?artnum=304263 …