{"id":67,"date":"2007-11-27T12:14:42","date_gmt":"2007-11-27T10:14:42","guid":{"rendered":"http:\/\/blog.intego.com\/2007\/11\/27\/quicktime-streaming-flaw-threatens-mac-and-windows\/"},"modified":"2007-11-27T12:14:42","modified_gmt":"2007-11-27T10:14:42","slug":"quicktime-streaming-flaw-threatens-mac-and-windows","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/","title":{"rendered":"QuickTime Streaming Flaw Threatens Mac and Windows"},"content":{"rendered":"<p>QuickTime has another weakness. A <a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/659761\">recently reported<\/a> flaw in Apple&#8217;s QuickTime software puts Mac and Windows users at risk of exploits that use RSTP (Real Time Streaming Protocol) URLs. Users clicking on streaming links may open their systems up to arbitrary code execution; that&#8217;s security-speak for bad code and bad mojo. For now, a proof-of-concept malware is circulating for Windows (<a href=\"http:\/\/erratasec.blogspot.com\/2007\/11\/new-rtsp-quicktime-flaw-affects-both.html\">this site explains in detail how this functions<\/a>), and nothing has been seen for Mac. But, as we have seen an alarming number of Mac-targeted exploits recently, it&#8217;s highly likely that a similar malware comes to light to attack Macs. Note that while some initial reports suggested that this vulnerability is only in QuickTime 7.3, CERT&#8217;s limited testing shows that &#8220;shown QuickTime versions 4.0 through 7.3 are vulnerable on all supported Mac and Windows platforms.&#8221; <\/p>\n<p>The best protection, until Apple releases a security update, is to use a firewall, such as <a href=\"https:\/\/www.intego.com\/netbarrier\/\">Intego NetBarrier<\/a>, to block ports used by the RTSP protocol: 554 TCP and UDP, 7070 TCP and UDP, and 8554 TCP and UDP. It&#8217;s best to avoid clicking on any streaming links, but these are not always indicated as such on web pages.  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>QuickTime has another weakness. A recently reported flaw in Apple&#8217;s QuickTime software puts Mac and Windows users at risk of exploits that use RSTP (Real Time Streaming Protocol) URLs. Users clicking on streaming links may open their systems up to arbitrary code execution; that&#8217;s security-speak for bad code and bad mojo. For now, a proof-of-concept [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[7,13],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"QuickTime has another weakness. A recently reported flaw in Apple&#039;s QuickTime software puts Mac and Windows users at risk of exploits that use RSTP (Real\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"QuickTime Streaming Flaw Threatens Mac and Windows - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"QuickTime has another weakness. A recently reported flaw in Apple&#039;s QuickTime software puts Mac and Windows users at risk of exploits that use RSTP (Real\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2007-11-27T10:14:42+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/\",\"name\":\"QuickTime Streaming Flaw Threatens Mac and Windows - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"datePublished\":\"2007-11-27T10:14:42+00:00\",\"dateModified\":\"2007-11-27T10:14:42+00:00\",\"description\":\"QuickTime has another weakness. A recently reported flaw in Apple's QuickTime software puts Mac and Windows users at risk of exploits that use RSTP (Real\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"QuickTime Streaming Flaw Threatens Mac and Windows\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"QuickTime Streaming Flaw Threatens Mac and Windows\",\"datePublished\":\"2007-11-27T10:14:42+00:00\",\"dateModified\":\"2007-11-27T10:14:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#webpage\"},\"wordCount\":195,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"articleSection\":[\"Apple\",\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"QuickTime has another weakness. A recently reported flaw in Apple's QuickTime software puts Mac and Windows users at risk of exploits that use RSTP (Real","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/","og_locale":"en_US","og_type":"article","og_title":"QuickTime Streaming Flaw Threatens Mac and Windows - The Mac Security Blog","og_description":"QuickTime has another weakness. A recently reported flaw in Apple's QuickTime software puts Mac and Windows users at risk of exploits that use RSTP (Real","og_url":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/","og_site_name":"The Mac Security Blog","article_published_time":"2007-11-27T10:14:42+00:00","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/","name":"QuickTime Streaming Flaw Threatens Mac and Windows - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"datePublished":"2007-11-27T10:14:42+00:00","dateModified":"2007-11-27T10:14:42+00:00","description":"QuickTime has another weakness. A recently reported flaw in Apple's QuickTime software puts Mac and Windows users at risk of exploits that use RSTP (Real","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"QuickTime Streaming Flaw Threatens Mac and Windows"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"QuickTime Streaming Flaw Threatens Mac and Windows","datePublished":"2007-11-27T10:14:42+00:00","dateModified":"2007-11-27T10:14:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/quicktime-streaming-flaw-threatens-mac-and-windows\/#webpage"},"wordCount":195,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"articleSection":["Apple","Security &amp; Privacy"],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-15","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/67"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=67"}],"version-history":[{"count":0,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/67\/revisions"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=67"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=67"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=67"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}