Latest QuickTime bug leaves XP, Vista vulnerable

Security researchers say that a new QuickTime flaw has gone public and leaves XP and Vista vulnerable to attack.

According to Secunia, the latest QuickTime bug "can be exploited by malicious people to compromise a user's system." A working exploit is public and the vulnerability has been confirmed for version 7.3. Secunia calls the bug "extremely critical."

Based on the original report from "h07," Apple apparently didn't enable a security feature. Here's h07's tale:

[*] On Vista the QuickTimePlayer and the .gtx modules dont have ASLR enabled, NO RANDOMIZATION :) [*]All the 7.3 and 7.2 DLL modules are SafeSEH enabled, except for the .gtx modules, that is how u bypass the SEH Restrictions in XP and in Vista!! so we use Addys from there. [*]There are ALOT of filtered characters so choose your shellcode wisely or you will run into Access Violations Since I didnt feel like wasting my time going through all the filtered Characters, go through it yourself. - Here are some \x4b, \x59, \x79 [*]I did hit my shellcode but b/c i havent gone through all the filtered characters i got an Access Violation in the shellcode [*]Can be easily modified to keep accepting clients with a lil modding, do it yourself u noobs

[***]Here is an example of how to embed a streaming the quicktime redirection to the RTSP exploit. cough use w/ an iframe cough

The U.S. computer emergency readiness team has more in plain old English. Key excerpts:

Apple QuickTime contains a stack buffer overflow vulnerability in the way QuickTime handles the RTSP Content-Type header. This vulnerability may be exploited by convincing a user to connect to a specially crafted RTSP stream. Note that QuickTime is a component of Apple iTunes, therefore iTunes installations are also affected by this vulnerability. We are aware of publicly available exploit code for this vulnerability.

By convincing a user to connect to a specially crafted RTSP stream, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. An attacker can use various types of web page content, including a QuickTime Media Link file, to cause a user to load an RTSP stream.

We are currently unaware of a practical solution to this problem. Please consider the following workarounds. Note that these workarounds will not address the vulnerability, but they may help block certain attack vectors for the vulnerability.

    • Thats strange .

      I find it strange that all these issues are affecting the Windows platform and not the
      Mac platform . I read about this issue at on Friday and ran
      into this other issue that Microsoft has been dragging their feet on for quite
      sometime .

      "Microsoft confirms that XP contains random number generator bug."
      It is just amazing to me that a company which has the resources Microsoft has
      would use a flawed random number generating algorithm when it could have easily
      bought a mature, field-tested, really secure version for use in its products. An
      intruder should not be able to predict the output of a decent random number
      generator - even if he has been given the exact details of the algorithm being used.
      Im betting APPLE will have their fix out the door before Microsoft
          • Leopard has been fixed already , can you say the same for vista .

            Vista has been out for over a year , and yet no service pack . Leopard has been out
            for a month and the updates already fixed the issues . What are you babbling about
            now ?
            If anything you should do your homework and realize that Microsoft has not yet
            fixed it's URI handler problem , to make matters worse , Microsoft's random
            number generator is serious flawed . Even a hacker could guess the output of the
            generator easily ,,,

            "Microsoft confirms that XP contains random number generator bug"


            So Microsoft finally admitted to that flaw the way they finally admitted the URI flaw
            , but no , you MS shills and zealots claimed it was Firefox's fault , no it's Safari's
            fault , it is the fault of every 3rd party developers . According to you folks it was
            never Microsoft's fault , guess what , Microsoft dropped the ball and admitted it's
            their fault . Do yourself and everyone else here a favor , and stop foaming at the
            mouth , you are making all Microsoft users look really BAD with your ignorance and
            personal attacks .
          • My guess is that Microsoft

            is introducing these bugs into XP so people will have a reason to move on to Vista . To
            be honest with you , like so many before me have stated , there is absolutely no
            compelling reason to move on to Vista . Fact , many are waiting for Windows 7 ,,,
