- Servers
- Desktops
- Laptops
- Tablet PCs
- PDAs
- Smart phones
- Digital cameras
- Camcorders
- Printers & multifunction devices
- Scanners
- Copiers
- Monitors & projectors
- Hard drives & burners
- Peripherals
- Productivity
- Accounting & finance
- Data management
- Graphics & publishing
- Web publishing
- Operating systems
- Security & utilities
- Downloads & trial software
- Handheld software
- Instant messaging
- Cell phones & plans
- Voice over Internet
- Telephones
- Routers & gateways
- Wireless networking
- Network adapters
- Internet access
- Web hosting
- Domain search
- Hotspot Zone
- Desktops
- Laptops
- Servers and storage
- PDAs
- Cell phones
- Monitors & projectors
- Printers
- Networking and wireless
- Security and utility software
- Productivity software
- Access, hosting, and services
- All business buying guides
CNET Security Center: Your complete source of antivirus and Internet security information.
A flaw in real-time streaming of QuickTime videos could allow remote attackers to compromise your Windows or Mac system.
By Robert Vamosi (January 2, 2007)
Date first reported: 01/01/07
Vulnerable software: Microsoft Windows and Mac OS X versions of QuickTime Version 7.1.3, Player Version 7.1.3, and earlier.
What it does: Could allow remote access and execution of malicious code.
Recommendations: Not clicking on links beginning with "rtsp://"; or disable the QuickTime rtsp:// URL handler; or uninstall Quicktime.
Exploit code available: Yes
Vendor patch available: No
At this time, there is no patch available from Apple. Users should avoid clicking URLs that begin with "rstp://." One workaround within QuickTime is to disable the rtsp:// URL handler. To do so, Mac users should open QuickTime, go to Preferences, click the Advanced tab, and select Mime Settings; once there, uncheck the box next to Streaming - Streaming Movies. For Windows users, click Edit, then Preferences, and then QuickTime Preferences. Select File Types from the pull-down menu or tab options. On the File Types page click Streaming - Streaming Movies to display additional options and uncheck the box next to RSTP stream descriptor if necessary.
Additional Resources:
NIST: CVE-2007-0015
MOAB: MOAB-01-01-2007
Milworm.com: 3064



