QT Hole-- Er, BUG-- Fixed (5/3/04)
SceneLink
 

Say, do you folks happen to remember that QuickTime vulnerability that surfaced a couple of months ago? Sure you do; after all, it's not like Mac security issues make the news every other day, right? (cough Sasser cough). The flaw we're talking about apparently made it possible for evildoers to "reliably overwrite heap memory with user-controlled data and execute arbitrary code in the context of the user who executed the players or application hosting the QuickTime plug-in." In other words, bad guys can do bad stuff to you from far away. Well, the good news is that Apple has fixed the problem. The bad news (maybe) is that the company doesn't seem to be telling anyone about it.

See, according to TechNewsWorld, the latest version of QuickTime corrects the bug, but Apple has refused to characterize the problem as a security flaw and, accordingly, hasn't exactly been shouting about the fix from the rooftops. Meanwhile, eEye Digital, the firm that discovered the flaw in the first place, baldly states that "Apple is doing a disservice to its customers by incorrectly labeling this vulnerability as a 'crash bug' rather than stating correctly that attackers can compromise systems running the affected Apple software." And "independent security expert" Ryan Russell says that Apple's behavior "hints that there is a real lack of maturity, or inexperience may be a better way to put it, with their response."

Well, duh; the company may release Security Updates every so often (2004-05-03 available now-- get it while it's hot!), but they almost never have to address a flaw that can actually grant scary people the ability to run code on a remote Mac; in contrast, Microsoft generally has literally three or four holes of that severity every month (or week or minute), so those guys are used to dealing with it. Russell implies that Apple will learn the ropes "with a little more experience." More experience? As in, Apple's going to start shipping more and more products with severe security problems? Unless Apple's hiring away all of Microsoft's "programmers," we're not holding our breath.

On the notification front, though, it's not like Russell and eEye don't have a valid point; after all, that Sasser worm that's currently running amok throughout the Wintel universe exploits a security hole that Microsoft plugged three weeks ago. Patches don't help if people don't use them. That said, at least one security expert thinks Apple may have been right not to issue an advisory: iDefense's Ken Dunham notes that "the likelihood of attack is lower" and "there's a benefit to not sending out such advisories, which might lend importance or risk." After all, it's no coincidence that all these Windows worms show up a few weeks after Microsoft has patched the hole they will eventually exploit; Microsoft says "hey, there's this hole, so run this patch," customers say "yeah, whatever, maybe later," virus guys say "neat, look at that hole we had no idea was there waiting to be exploited, let's write a worm because it's not like anyone's going to patch the problem until they have to." So maybe keeping mum's the right strategy for a lowish-risk flaw like this.

Whatever. Luckily, you don't have to wait for Apple to acknowledge the hole before you plug it. Heck, if you're in the U.S. it's likely you already did; the newly-released iTunes 4.5 requires QuickTime 6.5.1 to let you play iTunes Music Store tracks in non-iTunes applications, so the odds are pretty good that you grabbed it as soon as you had a chance. But if you didn't, now you know: 6.5.1 also fixes that security flaw-- er, crash bug-- that might have let the naughty people mess with your Mac. So install it already, because it's good for you.

 
SceneLink (4670)
And Now For A Word From Our Sponsors
 

From the writer/creator of AtAT, a Pandemic Dad Joke taken WAYYYYYY too far

 

The above scene was taken from the 5/3/04 episode:

May 3, 2004: Our irony registers may need recalibration, but at least we didn't get slapped with an antitrust fine like Bill Gates. Meanwhile, the San Francisco Chronicle picks Steve Jobs as its CEO of the Year (plus he works for cheap), and Apple plugs that QuickTime security flaw, without actually admitting its existence in the first place...

Other scenes from that episode:

  • 4668: Falling Irony: Hard Hat Zone (5/3/04)   Aaaaaaand here we are again, right back broadcasting late as usual. You know, we really thought we'd start this week off on time for once-- and we would have, too, if we hadn't had to take time out to answer about eleven hundred bajillion email messages telling us what an "arse" is...

  • 4669: Two For The Price Of None (5/3/04)   Steve Jobs, Steve Jobs, rah rah rah! That's right, folks, we're in full-on cheerleader mode for Big Steve, because we're not sure he's been getting enough praise lately, and our researchers have reason to believe that his Reality Distortion Field is powered by raw ego...

Or view the entire episode as originally broadcast...

Vote Early, Vote Often!
Why did you tune in to this '90s relic of a soap opera?
Nostalgia is the next best thing to feeling alive
My name is Rip Van Winkle and I just woke up; what did I miss?
I'm trying to pretend the last 20 years never happened
I mean, if it worked for Friends, why not?
I came here looking for a receptacle in which to place the cremated remains of my deceased Java applets (think about it)

(1287 votes)
Apple store at Amazon

As an Amazon Associate, AtAT earns from qualifying purchases

DISCLAIMER: AtAT was not a news site any more than Inside Edition was a "real" news show. We made Dawson's Creek look like 60 Minutes. We engaged in rampant guesswork, wild speculation, and pure fabrication for the entertainment of our viewers. Sure, everything here was "inspired by actual events," but so was Amityville II: The Possession. So lighten up.

Site best viewed with a sense of humor. AtAT is not responsible for lost or stolen articles. Keep hands inside car at all times. The drinking of beverages while watching AtAT is strongly discouraged; AtAT is not responsible for damage, discomfort, or staining caused by spit-takes or "nosers."

Everything you see here that isn't attributed to other parties is copyright ©,1997-2024 J. Miller and may not be reproduced or rebroadcast without his explicit consent (or possibly the express written consent of Major League Baseball, but we doubt it).