Apple QuickTime RTSP Buffer Overflow

A vulnerability has been found in the way QuickTime handles Real Time Streaming Protocol URL’s. Until Apple release a Software Update for this, it is recommended that users disable QuickTime support in their browsers. This is simple to do:

  1. Navigate to /Library/Internet Plug-Ins
  2. Drag the QuickTime Plugin.plugin and QuickTime Plugin.webplugin files to a temporary location, perhaps into your Documents folder
  3. Restart any open browsers, i.e. Safari, Firefox, Opera etc.

More information on this vulnerability can be found here:

US-CERT Vulnerability Note VU#442497

Leave a Reply