newsbot
11-08-2010, 11:40 AM
A highly dangerous remote code execution flaw has been exposed in the recent version of the QuickTime for Windows. Secunia (A Danish vulnerability intelligence vendor) reported that the security hole could be exploited by the hackers to scam users into watching a maliciously designed Web page. Security researcher, Krystian Kloskowski, said that the vulnerability originated owing to a boundary flaw in QuickTimeStreaming.qtx, when a string was constructed to inscribe to a debug log file, as reported by the Help Net Security on July 298, 2010. To abuse the QuickTime vulnerability, an attacker should deceive users into visiting a malicious web page that refers to a specifically designed SMIL file including an unusually lengthy URL. SMIL is primarily an XML based markup language used to describe diverse aspects of multimedia presentations, like elements, timeline and layouts.
**Hidden Content: Check the thread to see hidden data.**
**Hidden Content: Check the thread to see hidden data.**