Stephen Withers
Tuesday, 06 March 2007 08:51
Business IT -
Technology
Apple's latest QuickTime software patches a slew of security vulnerabilities in the Mac OS X and Windows versions that allow arbitrary code execution.
The vulnerabilities are triggered by maliciously crafted files of various kinds. The updated routines in QuickTime 7.5.1 provide additional checking to avoid crashes or arbitrary code execution.
The affected filetypes are 3GP (Windows only - the remaining vulnerabilities affect QuickTime for Mac OS X and Windows), MIDI, MOV, PICT and QTIF.
Some of the filetypes are subject to multiple vulnerabilities.
Since most Mac applications would use QuickTime to handle these file types, the update is especially important to Mac OS X users. While iTunes (see below) is the main QuickTime application for Windows, the update may be seen as less critical for users of Microsoft's operating systems. However, a number of multimedia titles are based on QuickTime, and it is possible for any of the common multimedia file types to be associated with QuickTime player - either by the user's deliberate action or at an application's behest.
QuickTime 7.1.5 also provides "numerous [unspecified] bug fixes" according to Apple.