QuickTime zero-day spotted

By
Follow google news

Flaw also affects latest iTunes.


Security experts are warning of a new zero-day vulnerability affecting Apple's QuickTime and iTunes players.

Known as a 'boundary condition error', the flaw exists in the player's handling of header information for multimedia files. An attacker could place specially-crafted XML code within an audio or movie file and cause the application to crash.

Discovery of the flaw was credited to a researcher using the handle 'securfrog'. There have been no reports of the vulnerability being targeted in the wild.

It is not yet known whether the crash would also allow for the remote execution of code on the target machine. The vulnerability exists in both the MacOS and Windows versions of the QuickTime 7.5.5 player and iTunes 8.0.

Security firm Intego is currently classifying the vulnerability as a low-risk flaw, though the danger from attack could increase significantly should remote code execution be found possible.

News of the vulnerability comes just days after Apple released major updates for both QuickTime and iTunes. In addition to new features, the updates contained numerous security patches.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Log In

  |  Forgot your password?