Security testing
Scanit offers penetration tests, vulnerability assessments and web application audits.
Learn ethical hacking.
Scanit offers 5-day training on ethical hacking.

Apple QuickTime 'QTPlugin.ocx' ActiveX Control Multiple Buffer Overflows ()

Description

Apple QuickTime ActiveX control allows viewing QuickTime movies and other multimedia in a browser. A number of buffer overflow problems were discovered in this control.

This is an arbitrary code execution vulnerability. It means that it can be used to place a backdoor, a virus or spyware on the vulnerable computer.

Recommendations

Currently Apple has not released a fix for this problem.

As a work-around you can disable QuickTime ActiveX control. This will prevent you viewing QuickTime content in your browser.

To disable QuickTime in Internet Explorer go to Tools menu, and choose "Internet Options...". In "Internet Options" dialog box select Programs tab and click on "Manage Add-ons..." button. In "Manage Add-ons" dialog select "Show add-ons that have been used by Internet Explorer" and select "QuickTime Object" in the list of add-ons. In the Settings box below click "Disable" and click "OK" button. Then click "OK" in the "Internet Options" dialog box and restart Internet Explorer.

References