Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Apple releases QuickTime update to patch seven vulnerabilities

  • Email a Friend
  • Print Page
Apple releases QuickTime update to patch seven vulnerabilities
By Dan Kaplan
Nov 7, 2007 9:56 AM
Tags: Apple | releases | QuickTime | update | to | patch | seven | vulnerabilities
The bugs, rated "highly critical" by tracking firm Secunia, are corrected in QuickTime 7.3 for Mac and Windows operating systems, according to an Apple security advisory.

The six most dangerous vulnerabilities are related to a memory corruption, a stack buffer overflow and four heap buffer overflows. The seventh vulnerability resides in Java and may permit untrusted applets to obtain privilege escalation.

"It looks like seven pretty nasty vulnerabilities that either due privilege escalation or code execution," Eric Schultze, chief technology officer of Shavlik Technologies, told SCMagazineUS.com today. "I would not go viewing a movie until I got this patched."

This is the fourth new version of QuickTime to be released this year, according to Apple.

"Apple is no better at security than Microsoft," Schultze said. "Everybody has equal numbers of flaws in their code."

Schultze said he recommends Windows and Mac users patch as soon as possible.

"You may not even know QuickTime exists on your box," he said. "They say there's an auto update in QuickTime, but it doesn't always update correctly. You're best off going to Apple's website and updating to the latest version."

An Apple spokesperson did not return a call for comment.

See original article on SC Magazine US

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers