This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

0-Day exploit for QuickTime posted

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

QuickTime RTSP vuln
> http://secunia.com/advisories/28423/
Release Date: 2008-01-11
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched
Software: Apple QuickTime 7.x
…requires that the user is e.g. tricked into opening a malicious QTL file or visiting a malicious web site. The vulnerability is reported in version 7.3.1.70. Other versions may also be affected.
Other References: US-CERT VU#112179:
http://www.kb.cert.org/vuls/id/112179
Last Updated: 01/10/2008

:ph34r:
FYI…

QuickTime 7.4 released
- http://forums.whatthetech.com/QuickTime_7_…sed_t87487.html
Post Date: January 15, 2008

- http://isc.sans.org/diary.html?storyid=3852
Last Updated: 2008-01-15 22:09:15 UTC - "…Note that this update does not yet appear to resolve the critical vulnerability reported last week by Luigi Auriemma (VU #112179*)."
* http://www.kb.cert.org/vuls/id/112179

> http://forums.whatthetech.com/QuickTime_7_…sed_t88560.html
QuickTime 7.4.1 released

:(