User User name Password  
   
Tuesday 24.11.2009 / 12:31 AM
Search AfterDawn.com:        In English   Suomeksi   På svenska
afterdawn.com > news > apple fixes two quicktime flaws
Show topics
News
News

Apple fixes two QuickTime flaws

31 May 2007 19:54 by James "Dela" Delahunty | 3 comments

Apple fixes two QuickTime flaws Apple Inc. has fixed more serious security bugs with QuickTime. This time, users tricked into visited malicious webpages could either have their privacy breached or worse, have arbitrary code executed on their computers. The patches released are for both Microsoft's Windows operating systems and the Mac platforms.

The worst of the two involved QuickTime's implementation of Java, which could allow for the manipulation of objects outside what should be allowed by the allocated heap. "By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution," Apple said in this advisory.

The second flaw deals also deals with how QuickTime works with Java, and can lead to a user's web browser information being stolen, possibly putting sensitive information at risk. Apple gave credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force and Dyon Balding of Secunia Research for reporting the flaws.

Source:
Reg Hardware


Permalink to this article

Get AfterDawn's news to your favourite feed reader! Share this story with your friends!
 

 
Related articles:

  • Apple patches security flaws in iPhone, QuickTime (16 January 2008)
  • Apple patches Windows Quicktime flaw (4 October 2007)
  •  

    « Previous news article
    PayPlay launches "the world's largest MP3 download store"
    Next news article »
    Set-top boxes and DTVs soon to get 60 FPS and 1080p decoding
     Post your comment
    Discuss this article! 
    thekingo7 (Senior Member) 1 June 2007 12:11 Send private message to this user   
    Quote:
    pple gave credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force and Dyon Balding of Secunia Research for reporting the flaws.
    Gave them credit?? I'm sure a small portion of the computer populace knew about this before these guys came along.
    borhan9 (AfterDawn Addict) 1 June 2007 19:18 Send private message to this user   
    Well thanxs for the update im going to update my quicktime now if it has flaws like this atm :)
    Unfocused (Member) 28 June 2007 6:09 Send private message to this user   
    At least they take the time to fix these vulnerabilities.
     Post your comment
     

    Subscribe to our newsfeed

    Get the latest headlines delivered directly to your favourite RSS reader or content aggregation service by using the links below.

    AfterDawn.com: News - RSS feed
    Add to Google
    Add to My Yahoo!
    Add to MyMSN

    Search for headlines

    Search through our news archive.

    Last week's most popular software downloads

    Digital video: AfterDawn.com | AfterDawn Forums
    Music: MP3Lizard.com
    Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
    Software: Software downloads
    Blogs: User profile pages
    RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
    International: AfterDawn in Finnish | AfterDawn in Swedish | download.fi
    Navigate: Search | Site map
    About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
    Contact us: Send feedback | Contact our media sales team
     
      © 1999-2009 by AfterDawn Ltd.