Apple Squashes QuickTime Bugs With New Update
By Max Brenn
00:10, December 15th 2007
65 votes
Vote this story
Apple Squashes QuickTime Bugs With New Update

Apple released today an update for its QuickTime application, via Mac OS X's Software Update utility and on the Web.

The update fixes at leas three security vulnerabilities, including the one revealed by Symantec.

Last month Symantec disclosed that Apple QuickTime contains a remote buffer overflow vulnerability that could be exploited by the hackers.Symantec rated the vulnerability as “high”.

“Apple QuickTime is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it to an insufficiently sized stack-based memory buffer. This issue occurs when handling specially crafted RTSP Response headers. Attackers can leverage this issue to execute arbitrary machine code in the context of the user running the affected application,” said Symantec at the time in its alert.

Another issue solved by QuickTime 7.3.1 regards the multiple vulnerabilities that exist in QuickTime's Flash media handler, the most serious of which may lead to arbitrary code execution.

“With this update, the Flash media handler in QuickTime is disabled except for a limited number of existing QuickTime movies that are known to be safe. Credit to Tom Ferris of Adobe Secure Software Engineering Team (ASSET), Mike Price of McAfee Avert Labs, and security researchers Lionel d'Hauenens & Brian Mariani of Syseclabs for reporting this issue” wrote Apple in its security advisory. The new version, QuickTime 7.3.1, is available for Mac OS X Panther, Tiger and Leopard and Windows.



© 2007 - 2008 - eFluxMedia
dotclear

Other News in

Internet Explorer Is Starting to Lose Ground

Internet Explorer Is Starting to Lose Ground

A new study released by Net Applications have shown that Microsoft’s Internet Explorer is starting to lose market share in favor of its two biggest competitors, Mozilla’s Firefox, and Apple’s...

Microsoft Equipt: Subscription Software More Expensive than Retail

Microsoft Equipt: Subscription Software More Expensive than Retail

Microsoft has launched the long-rumored subscription service to an all-in-one software suite, which combines Microsoft Office Home and Student 2007, Office Live Workspace, Windows Live OneCare,...

Viacom-YouTube Ruling Triggers Far-Reaching Privacy Concerns

Viacom-YouTube Ruling Triggers Far-Reaching Privacy Concerns

The ruling which demands Google to hand over the YouTube access logs, which are to show the actual extent of copyright infringement going on the popular site, has sparked outrage from privacy groups,...

Google Homepage Adds Privacy Link

Google Homepage Adds Privacy Link

Google's homepage at google.com has been changed: the search engine leader has decided that a privacy link, which leads to the company's straightforward Privacy Center, should be fit somewhere on its...

Is Powerset And The Semantic Search The Right Choice For Microsoft?

Is Powerset And The Semantic Search The Right Choice For Microsoft?

Desperate to reduce the gap between its search engine, Live Search, and omnipresent Google, Microsoft has been searching lately for the best solution. In just two months, Microsoft announced various...

dotclear
Latest videos in Technology
Microsoft after Gates
Mobile precautions urged
What Yahoo turned down
iPhones get faster, cheaper
Navigating social media

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Google Homepage Adds Privacy LinkGoogle Homepage Adds Privacy Link

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
Kent Couch Hopes To Fly 300 Mile In Lawn Chair Carried by BalloonsKent Couch Hopes To Fly 300 Mile In Lawn Chair Carried by Balloons

» read full story
dotclear