ProxySG Appliances Prevent Exploit Affecting iTunes and Other Applications Using QuickTime from Turning Computers into Bots or Hosts for Spyware
Blue Coat Systems, Inc. (Nasdaq: BCSI), a leader in WAN Application Delivery and Secure Web Gateway, today announced that its Blue Coat® ProxySG® appliances protect against the recently discovered security vulnerability in QuickTime software, a technology used with iTunes and other PC and Mac media applications. Malicious content disguised as or integrated with music or video that is accessed through QuickTime is automatically detected by ProxySG appliances deployed at a company or organization's Internet gateway and is prevented from gaining control of individual computers. To date, there is no patch or fix for this QuickTime software vulnerability, and Blue Coat ProxySG appliances currently may be the only available solution to provide protection from this vulnerability.
The QuickTime vulnerability potentially enables a criminal or hacker to take "root control" of an individual computer and to convert it into a so-called "zombie" used for malicious purposes as a part of a botnet or to plant spyware, such as framegrabbers or keyloggers, which can monitor and steal personal information. The vulnerability affects version 7.x of QuickTime software and results from a data boundary buffer overflow error when the QuickTime software processes Real Time Streaming Protocol (RTSP) replies.
"ProxySG appliances are a powerful solution for protecting against Web threats, including spyware, viruses and malicious code" said Mikko Valimaki, chief scientist, Blue Coat Systems, Inc. "Our appliances have visibility and understanding of users, content and applications and can use this information to apply appropriate controls. They can accelerate legitimate business-critical applications, manage or mitigate the effect of non-business applications and stop malicious traffic dead in its tracks."
ProxySG Appliances - Combining Security, Control and Acceleration
ProxySG appliances protect enterprises or organizations against malware, including viruses and spyware, provide URL filtering, anti-phishing capability, and manage the use of Internet applications for compliance with policy or for bandwidth consumption, including instant messaging, streaming media and peer-to-peer file sharing. ProxySG appliances also accelerate business-critical applications or content at the Internet gateway or across an organization's Wide Area Network (WAN). ProxySG appliances provide broad coverage for popular web protocols, including HTTP, SSL, FTP, SOCKS, IM, P2P and Streaming Content (RTSP, MMS) for an integrated secured web gateway solution.