Business Services Industry
Nevis Labs Identifies Vulnerability in Apple QuickTime
Business Wire, March 9, 2007
MOUNTAIN VIEW, Calif. -- Nevis Networks, a market leader in persistent LAN security solutions, today announced that Nevis Labs has identified a vulnerability in Apple QuickTime.
Affected Product/Versions: Apple QuickTime < 7.1.5
Product Overview: QuickTime is Apple's technology for handling video, sound, animation, graphics, text, music, and even 360-degree virtual reality (VR) scenes.
For more information visit http://www.apple.com/quicktime/
Vulnerability Details: This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime, both Windows and Mac. Minor user interaction is required. To exploit this vulnerability, the target must open a carefully crafted .mov file or visit a Web page embedding the malicious .mov file.
The specific flaw exists within the parsing of the size fields in the user-defined UDTA atoms of the .mov files. By setting this field to an overly large value, such as 0xFFFFFFFF, an integer overflow occurs resulting in an exploitable heap overflow.
Successful exploitation results in code execution under the context of the running user.
Vendor Response / Solution: Apple has issued an update to correct this vulnerability. More details can be found at: http://docs.info.apple.com/article.html?artnum=305149
Reference:
1. http://developer.apple.com/documentation/QuickTime/QTFF/index.html
2. http://docs.info.apple.com/article.html?artnum=305149
3. http://secway.org/advisory/AD20060512.txt
For more information: http://www.nevisnetworks.com
About Nevis Networks
Nevis Networks is the cost leader in Persistent LAN Security solutions that protect information privacy and integrity, provide user-based visibility, and maintain regulatory compliance. Nevis' innovative ASIC-based LANenforcer product line integrates pre-connect NAC functionality, with post-connect access control and threat detection, securing the Enterprise at wired, wireless, remote and branch office entry points. Nevis was founded in 2002 by seasoned executives with strong track records in security, semiconductor design, and networking technologies, and has raised over $40 million from veteran Silicon Valley investors New Enterprise Associates, BlueRun Ventures, and New Path Ventures. The company is headquartered in Mountain View, California, with additional R&D centers in Pune, India and Beijing, China.
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Most Recent Business Articles
- Psyadon Pharmaceuticals, Inc. Announces Regulatory Milestones and the Initiation of a Clinical Trial of Ecopipam in Lesch-Nyhan Disease
- Emergence of “Femtomedicine” - New Frontier of Biomed Sciences - Reported at First Global Congress on Nano Medicine
- Research and Markets: Ethiopia Power Market Outlook to 2020
- Research and Markets: Orphan Drugs in Asia-Pacific: from Designation to Pricing, Funding & Market Access
- Research and Markets: Now You See It - TV Program Sponsorship & Product Placement in China
Most Recent Business Publications
Most Popular Business Articles
- 7 tips for effective listening: productive listening does not occur naturally. It requires hard work and practice - Back To Basics - effective listening is a crucial skill for internal auditors
- FHM Features Anna Benson, Baseball's Hottest Wife
- Building a DNA database: the federal government has just enacted two bills related to DNA. The first would drive the collection of DNA from all infants. The second would attempt to prevent the DNA that is collected from being misused
- America's most wanted j-o-b-s - 10 hottest employment opportunities
- Developmental sequence in small groups


