Apple
Six QuickTime vulnerabilities could allow attackers to remotely execute code
R E L A T E D   C O N T E N T
ADVERTISEMENT

Apple releases seven QuickTime fixes

Vulnerabilities affect OS X and Windows versions

Shaun Nichols in California, vnunet.com 09 Nov 2007
ADVERTISEMENT

Apple has patched seven vulnerabilities in the latest version of QuickTime affecting the Windows and MacOS X versions of the media player software.

Each of the vulnerabilities affects users of MacOS 10.3.9, 10.4.9 and 10.5 as well as Windows XP and Vista.

Six of the vulnerabilities could allow attackers to remotely execute code on the targeted machine.

Three of the remote code execution vulnerabilities could be exploited when the user launches a specially-crafted movie file.

Two are exploited by way of malformed Pict files, and one can be targeted by way of a specially-crafted QuickTime VR file.

The update also addresses a flaw in the way QuickTime handles untrusted Java applets. Apple said that this could allow an attacker to run malicious Java code on the user's machine.

The update fixes the issue by preventing untrusted applets from running QuickTime's Java components.

Users can obtain the update through Apple's Software Update utility or the Apple Downloads site.

See also:

Apple iPhoneCounterfeiters target UK market ahead of official launch  08 Nov 2007
Apple iPhoneApple still has a lot to learn, say analysts  08 Nov 2007
Trojan horseOS X attack being served up with PC malware  01 Nov 2007
Apple iPhoneAll the latest news on Apple's iPhone  18 Dec 2007
Apple iTunesMajor upgrade to the media player  21 Nov 2008
QuickTimeMinor upgrade to the video player  10 Sep 2008

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Background A fantastic opportunity has just arisen within this growing multinational organisation. Working as an EMEA Advisory Consultant your main duties and responsibilities will be to provide advice and support to international organisations looking to ... more >
| Aston Carter
This is a hands-on development team lead position that will push you to the limit of your architectural and mentoring capabilities. Technical amp; development (Agile) • Create effective data solutions, in partnership with the relevant ... more >
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Computer People
Junior Network Operations Engineer – Borehamwood - £24k Junior / entry level network operations engineer required, will be responsible for supporting external clients network and security solutions. Excellent entry level position as my client offers ... more >
More job opportunities