Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Month of Apple Bugs Releases QuickTime Flaw

Add as a preferred source on Google

The Month of Apple Bugs project—a follow up to a Month of Kernel Bugs and A Month of Browser Bugs—vowed to release details of bugs and securty exploits in Apple’s Mac OS X operating system and popular Mac OS X applications…and the project is off and running, publicizing the details of a possible security exploit in Apple’s QuickTime software by overflowing buffers with specially crafted rtsp:// URLs. The bug impacts QuickTime 7.1.3 for both Mac OS X and Windows.

The Month of Bugs projects have been the center of some controversy; many software developers and security analysts feel it is irresponsible to publish the details of working security vulnerabilities in widely-available software, arguing that only feeds the ever-active malware communities lurking on the Internet’s dark underbelly and the possibility of real-world exploits. The responsible thing to do, they argue, is report the issues to the software vendors and security agencies, and publicize the details only when a patch or fix is available.

Recommended Videos

On the other hand, the “report and keep quiet” methodology rubs some people the wrong way: if their computers are vulnerable, they want to know the details now, regardless of whether a patch or fix is available, so at least they know what they’re up against. The participants in the Bug a Month projects—such as the “mysterious” programmer operating under the tag “LMH”—have also expressed frustration at the amount of time software developers like Apple and Microsoft take to patch seemingly trivial vulnerabilities.

In any case, it would appear that Apple’s Mac OS X and key applications—certainly not immune to security problems but thusfar spared the malware pain of the Windows world—are under a very public microscope.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
One of the most capable desktop processors available just got $125 cheaper: AMD Ryzen 9 9950X3D down to $573
AMD Ryzen 9 9950X3D drops to $573.99 (18% off): 16-core, 144MB cache, AM5, 3D V-Cache.
AMD Ryzen 9 9950X3D deal

The AMD Ryzen 9 9950X3D is down to $573.99 in a limited-time deal, a $125 saving off its $699 list price, and it represents something AMD hadn't offered before: a 3D V-Cache processor with a high enough core count to handle demanding creative and professional workloads without sacrificing the gaming performance that cache stacking delivers. For anyone running one machine for everything, this is the processor the 9000 series has been building toward.

get the deal

Read more
Adobe Firefly AI is now live publicly, hoping you’ll talk to an AI and get work done
Firefly AI Assistant can to handle your entire creative workflow
adobe-firefly-ai-assitant-public-beta

Adobe just opened up the public beta for Firefly AI Assistant. It is a conversational AI agent that sits across your entire Creative Cloud suite and handles multi-step workflows on your behalf.

You just have to describe what you want, and the assistant will figure out which Adobe tools to use and in what order, including Photoshop, Lightroom, Premiere, Firefly, and others.

Read more
Meta’s latest outrageous deal is getting solar power beamed even at night from satellites
Meta's deal with Overview Energy isn't just about clean power. It's a preview of what keeping AI running sustainably at planetary scale is going to require.
Satellite by Starlink

Out of all the things Meta has ever been accused of, thinking small hasn’t been one of them. 

The company that owns the most popular social media and messaging platforms like Facebook, Instagram, Messenger, and WhatsApp, is now looking at beaming sunlight from space to the Earth’s surface for powering its AI data centers after dark (via TechCrunch). 

Read more