On TV.com: Top 15 TV THEME Songs
BNET Business Network:
BNET
TechRepublic
ZDNet

November 26th, 2007

Latest QuickTime bug leaves XP, Vista vulnerable

Posted by Larry Dignan @ 6:45 am

Categories: Apple, Exploit code, Vulnerability research

Tags: Apple QuickTime, Microsoft Windows XP, Vulnerability, Microsoft Windows Vista, Ryan, Digital Music, Digital Media, Security, Personal Technology, Consumer Electronics

Security researchers say that a new QuickTime flaw has gone public and leaves XP and Vista vulnerable to attack.

According to Secunia, the latest QuickTime bug “can be exploited by malicious people to compromise a user’s system.” A working exploit is public and the vulnerability has been confirmed for version 7.3. Secunia calls the bug “extremely critical.”

Based on the original report from “h07,” Apple apparently didn’t enable a security feature. Here’s h07’s tale:

[*] On Vista the QuickTimePlayer and the .gtx modules dont have ASLR enabled, NO RANDOMIZATION :)
[*]All the 7.3 and 7.2 DLL modules are SafeSEH enabled, except for the .gtx modules, that is how u bypass the SEH
Restrictions in XP and in Vista!! so we use Addys from there.
[*]There are ALOT of filtered characters so choose your shellcode wisely or you will run into Access Violations
Since I didnt feel like wasting my time going through all the filtered Characters, go through it yourself.
- Here are some \x4b, \x59, \x79
[*]I did hit my shellcode but b/c i havent gone through all the filtered characters i got an Access Violation
in the shellcode
[*]Can be easily modified to keep accepting clients with a lil modding, do it yourself u noobs

[***]Here is an example of how to embed a streaming the quicktime redirection to the RTSP exploit.
http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html
cough use w/ an iframe cough

The U.S. computer emergency readiness team has more in plain old English. Key excerpts:

Apple QuickTime contains a stack buffer overflow vulnerability in the way QuickTime handles the RTSP Content-Type header. This vulnerability may be exploited by convincing a user to connect to a specially crafted RTSP stream. Note that QuickTime is a component of Apple iTunes, therefore iTunes installations are also affected by this vulnerability. We are aware of publicly available exploit code for this vulnerability.

By convincing a user to connect to a specially crafted RTSP stream, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. An attacker can use various types of web page content, including a QuickTime Media Link file, to cause a user to load an RTSP stream.

We are currently unaware of a practical solution to this problem. Please consider the following workarounds. Note that these workarounds will not address the vulnerability, but they may help block certain attack vectors for the vulnerability.

Also see Computerworld.

Ryan is on vacation.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 141 Talkback(s)
RE: Latest QuickTime bug leaves XP, Vista vulnerable
all of these vulnerabilities w/QT and the host that come up w/Windows in general are making more and more of a case for a Google everything model...sadly. hosted apps requiring no software other than... (Read the rest)
Posted by: techrepublic@... Posted on: 12/15/07 You are currently: a Guest | | Terms of Use
It's time to boicott QuickTime libraries due too many security flaws!  qmlscycrajg | 11/26/07
Thats strange .  Intellihence | 11/26/07
XP?  No_Ax_to_Grind | 11/26/07
OS X and XP are on par with age .  Intellihence | 11/26/07
hey leopard what part of it's appel software do you not understand  SO.CAL Guy | 11/26/07
Leopard has been fixed already , can you say the same for vista .  Intellihence | 11/26/07
Retarded?  Duke E. Love | 11/26/07
My guess is that Microsoft  Intellihence | 11/26/07
Carl you can't be serious , are you ?  Intellihence | 11/26/07
FUD FUD FUD FUD FUD FUD FUD!!!  orthocross | 11/26/07
Microsoft is intentionally INTRODUCING vaulnerablities  Ole Man | 11/26/07
That xplain the vulnerabilities  GuidingLight | 11/26/07
While they aren't vulnerabilities...  SpikeyMike | 11/27/07
Be careful what you ask for...  Cardinal_Bill | 11/26/07
Oh yeah...  Cardinal_Bill | 11/26/07
thats cuz os 9 blows  pcguy777 | 11/27/07
APPLE  justanitguy | 11/26/07
Message has been deleted.  Intellihence | 11/26/07
Wow, nice job of passing the buck  Badgered | 11/26/07
My Leopard was never stuck at the login , if anything it has been fixed .  Intellihence | 11/26/07
and I repeat  Badgered | 11/26/07
Perhaps...  rapson | 11/26/07
Come on carl you can't be serious ?  Intellihence | 11/26/07
Well, I wasn't...  rapson | 11/26/07
"Quicktime aint done till Windows won't run"  GuidingLight | 11/26/07
Whoops , this message was meant for Carl  Intellihence | 11/26/07
This message is for Guiding Light  Intellihence | 11/26/07
To the Leopard: that's easy  rapson | 11/26/07
its corporate sabotage  pcguy777 | 11/27/07
Unfortunately MORE than just BAD CODE  xuniL_z | 11/26/07
I don't find it strange at all  NonZealot | 11/26/07
What's even stranger is that  Intellihence | 11/26/07
Leopard is Grasping, all you have proven  GuidingLight | 11/26/07
Of course they are  rapson | 11/26/07
An additional CAMPUS site coming soon ;  Intellihence | 11/26/07
If Apple will have a fix out before Microsoft....  Confused by religion | 11/26/07
So all 3rd party apps developers that code for Windows  Intellihence | 11/26/07
To: Beyond the Vista a Laeopard is stalking  derekgore | 11/26/07
I already have.  osreinstall | 11/26/07
codec packs contain the same flawed quicktime libraries!!!  qmlscycrajg | 11/26/07
I thought they were lightweight.  osreinstall | 11/26/07
I've banned Apple products from my network  NonZealot | 11/26/07
You have a network!?  ego.sum.stig@... | 11/26/07
What on earth are you talking about?  NonZealot | 11/26/07
Ah, ok now...  ego.sum.stig@... | 11/26/07
Hehe, you are probably right  NonZealot | 11/26/07
So...  ego.sum.stig@... | 11/26/07
You really need to add to that list.  xuniL_z | 11/26/07
I use Google apps personally  NonZealot | 11/26/07
You just stated that you and your companies only use Microsoft products  Intellihence | 11/26/07
To the Leopard zealot:  NonZealot | 11/26/07
Non Zealot's network  crash89 | 11/26/07
They won't escort Non_Zealot to the door .  Intellihence | 11/26/07
I used to own 1 company  NonZealot | 11/26/07
What happened to your company ?  Intellihence | 12/02/07
RE: Latest QuickTime bug leaves XP, Vista vulnerable  systemx | 11/26/07
NO OS is immune from bad code!  Heatlesssun1 | 11/26/07
You forgot to mention  Intellihence | 11/26/07
You dorgot to mention wiped hard drives with Leapord.  No_Ax_to_Grind | 11/26/07
Are you drunk or something from the holiday bash ?  Intellihence | 11/26/07
Maybe that's because  frgough | 11/26/07
frgough your not searching to hard i got 688,000 Results heres 1  SO.CAL Guy | 11/26/07
Now show us the other 687,999 results .  Intellihence | 11/26/07
Finder Bug  rpmyers1 | 11/26/07
Shouldn't DEP protect form this?  Heatlesssun1 | 11/26/07
It's not as bad as XP's random number generator .  Intellihence | 11/26/07
I think a lot of it  frgough | 11/26/07
I think it's because bugs in MS products...  mdsmedia | 11/27/07
The problem is...  Qbt | 11/26/07
Message has been deleted.  Intellihence | 11/26/07
Message has been deleted.  Qbt | 11/26/07
Message has been deleted.  Intellihence | 11/26/07
Whatever you say, "Leopard Boy"  M.R. Kennedy | 11/26/07
No he's not  Shelendrea | 11/26/07
Yep. Inventing allies to get your point accross.  osreinstall | 11/26/07
re: No he's not  M.R. Kennedy | 11/26/07
Are you thinking.......  xuniL_z | 11/27/07
Goes to show how little you know of either of them  mdsmedia | 11/27/07
DB is also hot on Google technologies  xuniL_z | 11/27/07
Coming from a cheese-eater  Ole Man | 11/27/07
it's because of windoze poor design!  Linux Geek | 11/26/07
Speaking of dozers  larryl1234 | 11/26/07
Windows Users don't need to buy a MAC  xuniL_z | 11/26/07
Woo Hoo!  ego.sum.stig@... | 11/26/07
UAC mitigates this Apple's flaw  qmlscycrajg | 11/26/07
UAC does not mitigate this flaw , neither does DEP .  Intellihence | 11/26/07
UAC = limited privileges = no damages  qmlscycrajg | 11/26/07
UAC mitigates this Apple's flaw  qmlscycrajg | 11/26/07
Golly  ego.sum.stig@... | 11/26/07
UAC = limited privileges = no damages!  qmlscycrajg | 11/26/07
Still flying high I see  ego.sum.stig@... | 11/26/07
re: Golly  M.R. Kennedy | 11/26/07
And here was me thinking  ego.sum.stig@... | 11/26/07
He's just ticked at Apple  Ole Man | 11/27/07
MacOS users aren't used to the concept of restricted rights accounts  NonZealot | 11/26/07
And...  ego.sum.stig@... | 11/26/07
Poor ego doesn't understand  NonZealot | 11/26/07
Hmmm....  ego.sum.stig@... | 11/26/07
It has never been confusing for this Mac user .  Intellihence | 11/26/07
Message has been deleted.  Intellihence | 11/26/07
hahaha..and you think Windows users are USED to it??  mdsmedia | 11/27/07
I wonder  Badgered | 11/26/07
No need to "tootle" anywhere. Fix was already in.  xuniL_z | 11/26/07
What the heck is wrong with you today ?  Intellihence | 11/26/07
To use an americanism...  ego.sum.stig@... | 11/26/07
It comes as no surprise  xuniL_z | 11/27/07
Oh I've been told  ego.sum.stig@... | 11/27/07
....  Badgered | 11/27/07
ego.sum  derekgore | 11/26/07
Oh wait....  ego.sum.stig@... | 11/26/07
ego.sum  derekgore | 11/27/07
Mutton dressed up as lamb  ego.sum.stig@... | 11/27/07
No ego.sum  derekgore | 11/28/07
The point? Well Derek said it best i think  xuniL_z | 11/27/07
Look Mum...  ego.sum.stig@... | 11/27/07
oh my.  xuniL_z | 11/27/07
So your thesis is...  ego.sum.stig@... | 11/28/07
Yep, Apple had better tighten up, it's true  Ole Man | 11/27/07
I was going to drop this thread  NonZealot | 11/27/07
Aha!  ego.sum.stig@... | 11/27/07
the code is executed with the same user privileges  qmlscycrajg | 11/26/07
Doesn't mean much  rpmyers1 | 11/26/07
So how many users are affected?  sos10@... | 11/26/07
RE: Latest QuickTime bug leaves XP, Vista vulnerable  RS9 | 11/26/07
UR all a bunch of @$$'s  sykandtyed | 11/26/07
Wow, Deep thoughts with Jack Handy (nt)  tikigawd | 11/26/07
you actually were able to install qt on vista?  hpbear149 | 11/26/07
Why isn't Mac OS X affected?  John Musbach | 11/26/07
QT for OS X...  DCMann | 11/27/07
RE: Latest QuickTime bug leaves XP, Vista vulnerable  Narr vi | 11/27/07
Well...  ericm770@... | 11/27/07
When you have to hang your head in shame  Ole Man | 11/27/07
Well, gosh darn it...  ego.sum.stig@... | 11/27/07
You would make a noble leader!  Ole Man | 11/27/07
Or Stevie J!  derekgore | 11/28/07
I'd do it for the emotional satisfaction  ego.sum.stig@... | 11/28/07
Pfffft...  thx-1138_@... | 11/28/07
FUD?  SouthernBear | 11/30/07
Another GOOD reason to go Mac...  3dtodd | 12/14/07
...because they purposely LEAVE HOLES  Feldwebel Wolfenstool | 12/15/07
RE: Latest QuickTime bug leaves XP, Vista vulnerable  techrepublic@... | 12/15/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here