Several security fixes included in AppleTV update

By Ed Oswald | Published July 11, 2008, 3:45 PM

While the upgrade to the company's set-top box was advertised as adding support for remote control of iTunes and MobileMe, it also fixed some potentially serious flaws.

All six of the issues addressed with this last batch of patches deal with the potential for arbitrary code execution, with all but one also possibly leading to crashes of the device. Three of the flaws can be exploited through movie files, two through QuickTime, and the last through PICT images.

Of the movie file issues, all deal with the handling of so-called "atoms," which are bits of data in the QuickTime spec that hold various bits of information, such as title, codec identifiers, the encoded data, and so forth.

Heap buffer overflows could occur in the data reference, 'crgn', and 'chan' atoms, which could be used to launch arbitrary code and crash the device. To fix it, Apple added additional validation of the data reference atoms, while adding improved bounds checking to the latter two.

The QuickTime flaws address problems with the handling of file:// URLs, and HTTP responses when RTSP is enabled. The latter is again fixed by improved bounds checking, while the file:// URL issue is fixed by not permitting AppleTV to launch those URLs.

Finally, the PICT image issue occurs when a compressed PICT image is processed. If a maliciously crafted one is opened, it could allow for code to be executed or cause crashes. Apple said improved bounds checking here will also solve the problems.

Comments

They added a new "clear" option on the YouTube search menu. Yippee! When might we get RSS feed reading?

Score: 0

|

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Dish users may continue using DVRs as appeals court stays injunction

An injunction that was slated to go into effect soon, shutting off Dish Network customers DVRs and preventing their future sale, has been put on hold.

What's Now: Recording industry wins big against Usenet file sharing service

Plus: A Linux developer cuts back on the FAT, and now Nvidia's at loggerheads with Apple.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Google talks spam trends, spiffs up Gmail labels

More organization, a little less riff-raff in your inbox.

ASCAP wants money for your ringtone

'Performances' ought to be compensated, says composers' group.

The law vs. the right to know: Whose news is it anyway?

Lockdown with Angela Gunn An appeals court judge would award 'control' of a news item to its biggest reporter.

A Michael Jackson post-mortem on Internet journalism

Scott Fulton On Point An artist is being laid to rest, and something that would purport to be the new electronic press is congratulating itself prematurely.