Apple posts QuickTime 7.3.1 security update

Posted:
in macOS edited January 2014
Apple on Thursday night issued a hotfix for its QuickTime media player that patches a single but already exploited flaw in the software's handling of streaming content.



The exploit sends an improper header through QuickTime's Real Time Streaming Protocol (RTSP) service, triggering a buffer overflow that permits a hacker to run their own code and compromise an affected system.



In recent days, a website known as Ourvoyeur.net has reportedly been hijacked and used to infect systems with malware that opens a back door for hackers. That exploit targets Windows users but could theoretically apply to Mac OS X as well given the existence of the flaw in Apple's own operating system, according to one report.



The QuickTime patch is available both for the critically affected Windows systems in a 20MB download but is also offered as a roughly 50MB fix for Mac OS X Panther, Tiger, and Leopard.
«1

Comments

  • Reply 1 of 35
    shogunshogun Posts: 362member
    I'm patched, but is there a way to know if you've been "backdoored"?
  • Reply 2 of 35
    asciiascii Posts: 5,936member
    I'm so sick of these endless security holes in Quicktime. Is there any way to remove this plugin from a Mac without breaking Safari?
  • Reply 3 of 35
    MarvinMarvin Posts: 15,326moderator
    Quote:
    Originally Posted by ascii View Post


    Is there any way to remove this plugin from a Mac without breaking Safari?



    Remove the quicktime components from /Library/Internet plug-ins.



    I like that there's a link to a voyeur site in the article.
  • Reply 4 of 35
    jeffdmjeffdm Posts: 12,951member
    Quote:
    Originally Posted by Marvin View Post


    Remove the quicktime components from /Library/Internet plug-ins.



    I like that there's a link to a voyeur site in the article.



    Unless something changed, they said the name of the site, but there is no web link.
  • Reply 5 of 35
    pbpb Posts: 4,255member
    Quote:
    Originally Posted by JeffDM View Post


    Unless something changed, they said the name of the site, but there is no web link.



    Though there is no clickable web link, there is the complete URL of the site. Just out of curiosity, and after having applied the update, I entered the URL into Firefox to see what it gives. So, it is a nudity site and Firefox suddenly started hitting hard the hard disk and the UI almost froze up. I tried to kill it and it worked after several seconds of hard disk grinding. I hope it did nothing to my computer.
  • Reply 6 of 35
    I installed this patch along with the Rockband one that the software update recommended. Between them they seem to have gobbled up about 200MB of disk space ? is this normal?
  • Reply 7 of 35
    jeffdmjeffdm Posts: 12,951member
    Quote:
    Originally Posted by PB View Post


    Though there is no clickable web link, there is the complete URL of the site.



    That's pretty much what I said, but worded differently.
  • Reply 8 of 35
    pbpb Posts: 4,255member
    So, I was in a hurry and I did not finish my previous message: after my experience with the afore mentioned site, I think Kasper should edit the original article and remove the URL. Or provide just the site name without the extension. Or something anyway. No joking.
  • Reply 9 of 35
    jeffdmjeffdm Posts: 12,951member
    Quote:
    Originally Posted by PB View Post


    So, I was in a hurry and I did not finish my previous message: after my experience with the afore mentioned site, I think Kasper should edit the original article and remove the URL. Or provide just the site name without the extension. Or something anyway. No joking.



    It's not a complete URL, it's just the domain name. In order to even go there you still have to manually enter it.
  • Reply 10 of 35
    bsenkabsenka Posts: 799member
    Quote:
    Originally Posted by AppleInsider View Post


    ...could theoretically apply to Mac OS X as well...







    Could theoretically apply.



    I can't wait to see ZDnet spin this as another "oh noes!" story. This is an example of great proactive work by Apple. They consistently fix potential problems while they ARE simply potential.
  • Reply 11 of 35
    pbpb Posts: 4,255member
    Quote:
    Originally Posted by JeffDM View Post


    It's not a complete URL, it's just the domain name. In order to even go there you still have to manually enter it.



    Yes, you can manually enter it since you know it. It is a site with explicit nudity and reportedly a platform for attacks. It should go away. Just my opinion.
  • Reply 12 of 35
    Quote:
    Originally Posted by PB View Post


    Yes, you can manually enter it since you know it. It is a site with explicit nudity and reportedly a platform for attacks. It should go away. Just my opinion.



    I just thought I could give it a try (just out of curiosity). Bad idea. Safari just gone nuts.

    After the patch i should mention.
  • Reply 13 of 35
    jeffdmjeffdm Posts: 12,951member
    "Do not look into laser with remaining eye"
  • Reply 14 of 35
    When I installed this, it crashed my system, and when I restarted and logged in, Apple tried to tell me that I hadn't registed my MBP. After various combinations of restarting, registering, quitting, and reseting things (pram and pmu), and finally trying to repair my disk from the leopard disk, I had to archive and reinstall . Everything works now, but was a big waste of time. Now All updates since installing leopard are gone (10.5.1 mainly) and I'm kinda scared to try the quicktime one again.
  • Reply 15 of 35
    pbpb Posts: 4,255member
    Quote:
    Originally Posted by JeffDM View Post


    "Do not look into laser with remaining eye"



    LOL, good one.
  • Reply 16 of 35
    lkrupplkrupp Posts: 10,557member
    Quote:
    Originally Posted by Shogun View Post


    I'm patched, but is there a way to know if you've been "backdoored"?



    All of the exploits for this flaw were for Windows only. There are no reports of Mac users being 'backdoored'? Feel better now?
  • Reply 17 of 35
    MarvinMarvin Posts: 15,326moderator
    Quote:
    Originally Posted by PB View Post


    Though there is no clickable web link, there is the complete URL of the site. Just out of curiosity, and after having applied the update, I entered the URL into Firefox to see what it gives. So, it is a nudity site and Firefox suddenly started hitting hard the hard disk and the UI almost froze up. I tried to kill it and it worked after several seconds of hard disk grinding. I hope it did nothing to my computer.



    Same thing here. Although you have to copy/paste the link, I was curious as to what was on it and bam within a few seconds, everything just freezes up gradually. Fortunately I was able to force quit Safari but I think there should at least be a warning about what visiting the site will do in the article.



    I don't even think that's the effect the article is about because the exploit only targets windows so something else is screwed up on that site.
  • Reply 18 of 35
    jeffdmjeffdm Posts: 12,951member
    Quote:
    Originally Posted by Marvin View Post


    Same thing here. Although you have to copy/paste the link, I was curious as to what was on it and bam within a few seconds, everything just freezes up gradually. Fortunately I was able to force quit Safari but I think there should at least be a warning about what visiting the site will do in the article.



    What do you need to call it a warning, blinky lights? A yellow triangle?



    In the same sentence, right after the site name: "has reportedly been hijacked and used to infect systems with malware that opens a back door for hackers". I'd think that should be more than a hint to not tempt fate.
  • Reply 19 of 35
    mydomydo Posts: 1,888member
    Quote:
    Originally Posted by JeffDM View Post


    "Do not look into laser with remaining eye"



    I know a laser lab that has that posted on the wall.
  • Reply 20 of 35
    Quote:
    Originally Posted by PB View Post


    Though there is no clickable web link, there is the complete URL of the site. Just out of curiosity, and after having applied the update, I entered the URL into Firefox to see what it gives. So, it is a nudity site and Firefox suddenly started hitting hard the hard disk and the UI almost froze up. I tried to kill it and it worked after several seconds of hard disk grinding. I hope it did nothing to my computer.



    Someone once said, "Curiosity killed the cat."
Sign In or Register to comment.