|
31 May 2007 19:54 by James "Dela" Delahunty
| 3 comments
Apple Inc. has fixed more serious security bugs with QuickTime. This time, users tricked into visited malicious webpages could either have their privacy breached or worse, have arbitrary code executed on their computers. The patches released are for both Microsoft's Windows operating systems and the Mac platforms.
The worst of the two involved QuickTime's implementation of Java, which could allow for the manipulation of objects outside what should be allowed by the allocated heap. "By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution," Apple said in this advisory.
The second flaw deals also deals with how QuickTime works with Java, and can lead to a user's web browser information being stolen, possibly putting sensitive information at risk. Apple gave credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force and Dyon Balding of Secunia Research for reporting the flaws.
Source:
Reg Hardware
Permalink to this article
| |
Related articles:
Apple patches security flaws in iPhone, QuickTime (16 January 2008)
Apple patches Windows Quicktime flaw (4 October 2007)
|
|
|
| Discuss this article! |
| thekingo7 (Senior Member) 1 June 2007 12:11 |
|
Quote: pple gave credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force and Dyon Balding of Secunia Research for reporting the flaws.
Gave them credit?? I'm sure a small portion of the computer populace knew about this before these guys came along.
|
| borhan9 (AfterDawn Addict) 1 June 2007 19:18 |
|
|
Well thanxs for the update im going to update my quicktime now if it has flaws like this atm :)
|
| Unfocused (Member) 28 June 2007 6:09 |
|
|
At least they take the time to fix these vulnerabilities.
|
|
|
Latest newsLatest news from AfterDawn.com. Spotify now available on Symbian phones 23 Nov, 2009 Sony confirms 'premium level' for PSN 23 Nov, 2009 | 9 comments Nintendo announces DSi holiday bundles 23 Nov, 2009 iPhone worm can steal banking data 23 Nov, 2009 | 4 comments Roku adds 10 new content channels 23 Nov, 2009 | 5 comments Google Navigation hacked to work outside of US, and on G1 23 Nov, 2009 | 2 comments DSi LL launches in Japan 23 Nov, 2009 | 1 comment China Unicom has bold expectations for iPhone 23 Nov, 2009 | 2 comments Windows 8 coming in 2012? 22 Nov, 2009 | 26 comments Hulu will be dead in two years, says Verizon CEO 22 Nov, 2009 | 7 comments Netflix to stream IFC films 22 Nov, 2009 | 4 comments Wal-Mart selling $78 Blu-ray player on Black Friday, other great deals 22 Nov, 2009 | 5 comments
More news... 
Search for headlinesSearch through our news archive. 
Latest threadsRecently updated discussion threads. More... 
Last week's most popular software downloads
Most popular devicesLast week's most popular products in our product comparison service. More products... 
Top linksMost popular links - Blasteroids.com
Download game trailers, demos and more - TorrentReactor.Net
The most active torrents on the web - Digital-Digest
Latest DivX, XviD, DVD, Blu-Ray, HD DVD News - OpenSubtitles.org
download DivX subtitles from the biggest open database - CDRInfo.com
The Hardware Authority - DVDHelp.us
DVD help, tutorials, FAQ, and very popular free help forum! - dvd ripper
rip DVD to VCD, DivX, MPEG, SVCD, AVI easily and quickly. - Torrentreactor.TO
The most active torrents on the web

|