Several security fixes included in AppleTV update

By Ed Oswald | Published July 11, 2008, 3:45 PM

While the upgrade to the company's set-top box was advertised as adding support for remote control of iTunes and MobileMe, it also fixed some potentially serious flaws.

All six of the issues addressed with this last batch of patches deal with the potential for arbitrary code execution, with all but one also possibly leading to crashes of the device. Three of the flaws can be exploited through movie files, two through QuickTime, and the last through PICT images.

Of the movie file issues, all deal with the handling of so-called "atoms," which are bits of data in the QuickTime spec that hold various bits of information, such as title, codec identifiers, the encoded data, and so forth.

Heap buffer overflows could occur in the data reference, 'crgn', and 'chan' atoms, which could be used to launch arbitrary code and crash the device. To fix it, Apple added additional validation of the data reference atoms, while adding improved bounds checking to the latter two.

The QuickTime flaws address problems with the handling of file:// URLs, and HTTP responses when RTSP is enabled. The latter is again fixed by improved bounds checking, while the file:// URL issue is fixed by not permitting AppleTV to launch those URLs.

Finally, the PICT image issue occurs when a compressed PICT image is processed. If a maliciously crafted one is opened, it could allow for code to be executed or cause crashes. Apple said improved bounds checking here will also solve the problems.

Comments

View comments by with a score of at least

They added a new "clear" option on the YouTube search menu. Yippee! When might we get RSS feed reading?

Score: 0

|

Exchange Server 2010 goes live, will extend rights-managed e-mail to browsers

A new feature will give companies a way to prevent users from manipulating e-mail content they receive based on what the messages contain.

Firefox turns five: Thanks for giving us a choice

Carmi Levy | Wide Angle Zoom: No longer the phoenix rising from the ashes, Mozilla has carried on more than just Netscape's legacy.

If Microsoft sites lead time online, pigs can fly

How can people spend more time at Microsoft sites, when the measure of success is Windows Live Messenger, which sits on the desktop?

Google Chrome 4: Yes, it's fast, but is it usable?

As Betanews readers have responded to our stories about Chrome's JavaScript superiority...Does that mean we'd actually use this browser? Well...

Microsoft's Top 3 advances in Exchange Server 2010

The latest round of changes launched today will impact how admins deliver services to e-mail recipients, and how much companies will pay along the way.

Qualcomm: $1.3 billion Samsung licensing deal unrelated to fair trade violations

Samsung has come to a 15-year licensing deal with Qualcomm over 3G and 4G wireless technology.

Nokia's 'limited number' of recalled chargers exceeds 14 million

Today, the Finnish phone maker has begun a recall of mobile phone chargers that are a shock hazard.

Ubuntu 9.10 upgraders report frustration

For those Wine aficionados out there, beware of the remote possibility that your Linux system could be infected by Windows-seeking malware.

Supreme Court considers patentability of abstract methods today

Can software that executes a formula for a business process qualify for federal patents? An appeals court already said no, and inventors are making their case.

Thanks, iPhone: Google buys mobile advertiser AdMob for $750 million

AdMob came to thrive thanks to the iPhone's popularity, now Google has bought it.

Myka announces its latest Linux-based 'net top box'

Myka's ION brings Boxee, XMBC, and much more to HDTVs.