Apple Squashes QuickTime Bugs With New Update

By Max Brenn
00:10, December 15th 2007
98 votes
Vote this story
Apple Squashes QuickTime Bugs With New Update

Apple released today an update for its QuickTime application, via Mac OS X's Software Update utility and on the Web.

The update fixes at leas three security vulnerabilities, including the one revealed by Symantec.

Last month Symantec disclosed that Apple QuickTime contains a remote buffer overflow vulnerability that could be exploited by the hackers.Symantec rated the vulnerability as “high”.

“Apple QuickTime is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized stack-based memory buffer. This issue occurs when handling specially crafted RTSP Response headers. Attackers can leverage this issue to execute arbitrary machine code in the context of the user running the affected application,” said Symantec at the time in its alert.

Another issue solved by QuickTime 7.3.1 regards the multiple vulnerabilities that exist in QuickTime's Flash media handler, the most serious of which may lead to arbitrary code execution.

“With this update, the Flash media handler in QuickTime is disabled except for a limited number of existing QuickTime movies that are known to be safe. Credit to Tom Ferris of Adobe Secure Software Engineering Team (ASSET), Mike Price of McAfee Avert Labs, and security researchers Lionel d'Hauenens & Brian Mariani of Syseclabs for reporting this issue” wrote Apple in its security advisory. The new version, QuickTime 7.3.1, is available for Mac OS X Panther, Tiger and Leopard and Windows.



© 2007 - 2008 - eFluxMedia
dotclear

Other News in

Yahoo Teams Up With CBS

Yahoo Teams Up With CBS

Wednesday Yahoo Inc. has announced its decision to take its Internet radio service to CBS Corp. Beginning in February 2009, CBS will power Yahoo-owned Launchcast and sell ads on the service, but...

Apple Removes Article About Antivirus Utilities

Apple Removes Article About Antivirus Utilities

Apple has removed an old item from its support site late Tuesday, one which advised Mac customers to use multiple antivirus utilities. Apple representatives now say that the Mac is safe “out of the...

Will January Bring Windows Beta 7?

Will January Bring Windows Beta 7?

A blog posting on Microsoft's Technet by Keith Combs hinted on Tuesday that a beta version for the company’s new operating system Windows 7 would be made available as early as January,...

Apple Briefly Posted Virus Warning, Subsequently Removed

Apple Briefly Posted Virus Warning, Subsequently Removed

Traditionally, one of the big selling points of Apple’s Mac OS X, one that the company has not neglected to boast as often as possible, was that the software is less susceptible to viruses than...

YouTube and Classical Music: Welcome to the Real World!

YouTube and Classical Music: Welcome to the Real World!

YouTube plans to bring culture to the masses and undiscovered talents to the most notorious concert halls, as the world leading video-sharing website is going to hold an online competition; the...

dotclear
Latest videos in Technology
Beauty and the PC
Nokia goes multi-sensory with...
Search for insight through...
The human face of robotics
'Karma' For Plug-In Hybrid

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Apple Recommends Antivirus For Mac Users. Or NotApple Recommends Antivirus For Mac Users. Or Not

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
R&B Singers Sued By PhotographerR&B Singers Sued By Photographer

» read full story
dotclear