Month of Apple Bugs Begins--Web Site Established and First Two Bugs Announced--Fixes Coming
Is this an attack, revenge, conspiracy or some kind of evil plot against Apple and the users of Apple products?
Not at all, some of us use OS X on a daily basis. Getting problems solved makes that use a bit more safe each day, for everyone else. Flaws exist, with and without people disclosing them. If we wanted to make business out of this we would be selling the issues and the proper exploit for each one. Thus, business-wise, we are wasting a good cake with this project (although software by Apple isn't really of interest in these terms, except iTunes and other applications).
Their first bug announcement, dated January 1, is a vulnerability called "QuickTime rtsp URL Handler Stack-based Buffer Overflow" with the description:
A vulnerability in the handling of the rtsp:// URL handler [in QuickTime 7.1.3] allows remote arbitrary code execution.
The bug is under review by the Common Vulnerabilities and Exposures (CVE) Editorial Board.
The second bug announcement, dated January 2, is a vulnerability called "VLC Media Player udp:// Format String Vulnerability" with the description:
A vulnerability in the handling of the udp:// URL handler allows remote arbitrary code execution.
This bug was not yet under review by CVE Editorial Board at publication time.
In response, Landon Fuller will try to issue a fix per day. In Fuller's blog, he states:
So, part brain exercise, part public service, I've created a runtime fix for the first issue using Application Enhancer. If I have time (or assistance), I'll attempt to patch the other vulnerabilities, one a day, until the month is out.
That's a constructive response but we think we'll pass until Apple issues a fix. Look for a new bug to be listed for January 3rd. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?