You're viewing an article in iPO's historic archive vault. Here, we've preserved the comments and how the site looked along with the article. Use this link to view the article on our current site: Potential Security Flaw in iTunes, QuickTime

News

Potential Security Flaw in iTunes, QuickTime

Security-Protocols is reporting that there is a possible security problem in QuickTime and iTunes for both Mac and Windows users. The security risk, called a Heap Overflow, affects Mac OS X 10.4.3 and Windows PCs capable of running Win32 code. The flaw was tested with QuickTime 7.0.3 and iTunes 6.0.1, but the report claims that all version are at risk.

The security risk takes advantage of a Heap Overflow caused by a specially crafted .MOV file to crash QuickTime and iTunes, allowing an attacker to potentially run arbitrary code.

The report also notes that Apple has been notified of the security issue. Apple does not publicly respond to security issues until a fix is available.

1 comments from the community.

You can post your own below.

+ show options

Your current settings, click to change: Sort Oldest First, Show Guest Posts, Hide Community Stats

Tiger said:

member since 17 Jun 2003 with 1018 posts, unranked, send him a message or view his profile

Pardon my ignorance, but do Macs on 10.4.3 actually RUN Win32 code?

And specially crafted meaning what, that they found a way around requiring user authentication to execute something?

Quote this post ↓

Post Your Comments

  Remember Me

Not a member? Register now. You can post comments without logging in, but they'll show up as a "guest" post.


Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.