Security Hole in Windows' QuickTime Player
Zonoprh writes "A Security Hole was found in QuickTime player that allows attackers to compromise a user's system with a malicious URL. The hole is fixed in QuickTime 6.1 available here. Until then, hold off on playing "unusually" enticing QT files."
How much good will this do in the Apple section if the bug is in the Windows version?
omnia tua castra sunt nobis
Had windows used a decent method of starting applications (instead of some stupid extension to DOS) then this overflow wouldn't happen. Yes, yes, I know, Apple should have checked for this overflow. However 1 kludge + 1 workaround != 1 good system.
*sigh*
I am artificially intelligent.
QuickTime 6.1.1 is also available on software update. Seems to container mpeg 4 streaming bug fixes.
Since when do notices of security holes that have been fixed for months rate /. articles?
"The worst tyrannies were the ones where a governance required its own logic on every embedded node." - Vernor Vinge
until then, hold off on playing "unusually" enticing QT files.Umm... QuickTime 6.1 was released on January 9th; I would think most people would already have this patched.
"Reality is just a convenient measure of complexity" -Alvy Ray Smith
WTF do you mean "extension to DOS"? You mean command line parameters (arguements)? Unix does the same thing. There are plenty of ways around using parameters under Windows, but they're more trouble to code for (IMO) for such a simple task, and not backward compatible - there is nothing wrong with the parameter method as long as idiot programms check their fucking buffers.
Opportunity knocks. Karma hunts you down.
Keep the Quicktime Player. Throw out your copy of Windows.