Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Does the new QuickTime 0-day mean Apple has Problems with Patching?

0
Posted

Does the new QuickTime 0-day mean Apple has Problems with Patching?

0

In the past Microsoft has been criticised for poor vulnerability patching (by not patching the underlying vulnerability that is causing a problem and then having to reissue patches as attackers adjust and attack), and it is a criticism that has also been levied against Apple with the handling of different mDNSResponder vulnerabilities. Recently disclosed vulnerability information regarding another RTSP handling problem in QuickTime could be a sign of a similar problem brewing. RTSP vulnerabilities were patched no less than four times in the last twelve months (Security Update 2007-001, Security Update 2007-004, Darwin Streaming Server 5.5.5, and QuickTime 7.3.1), and it seems that there are still opportunities for remote code execution within the RTSP code handling routines. A minor blessing with the latest vulnerability disclosure seems to be that the vulnerability does not appear to affect the latest version of OS X (10.5.1), at least according to early reports from third party teste

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123