Advertisement
Promo

Security threats Toolkit

Apple releases QuickTime security update

Robert Vamosi CNET News

Published: 30 May 2007 13:41 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple released a security update for QuickTime 7.1.6 on Tuesday, further removing a vulnerability first used by a security researcher in April to win $10,000 (£5,064) and a new MacBook in the "PWN to OWN" contest at CanSecWest 2007.

This security update complements an earlier bug patch for QuickTime 7.1.6 released by Apple on 1 May, 2007. The 1.1MB Windows QuickTime 7.1.6 update affects users of Windows 2000 SP4 and Windows XP SP2. The 1.4MB Mac QuickTime 7.1.6 update affects users of Mac OS X v10.3.9 and Mac OS X v10.4.9.

The vulnerability, as reported in a security alert from the US National Vulnerability Database, allows attackers to entice users to a website with a maliciously coded Java applet and then run attack code on a compromised machine. The Apple security update places further parameter limitations on QTPointerRef objects in Apple QuickTime Java extensions within the Safari and Firefox browsers, denying these types of attacks. Apple credits security researcher Dino Dai Zovi, working with TippingPoint and the Zero Day Initiative, for his help in resolving this issue.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
2 out of 2 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters