Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter
Apple fixes QuickTime vulnerabilities, eases iTunes/Vista compatibility woes E-mail
by Stephen Withers   
Tuesday, 06 March 2007
An update to Apple's QuickTime software patches a slew of vulnerabilities affecting Windows 2000, XP and Vista, as well as Mac OS X 10.3.9 and later. The problems it addresses are serious, as they provide opportunities for arbitrary code execution. The company has also delivered a new version of iTunes for Mac and Windows, improving Vista compatibility.

Several of the QuickTime vulnerabilities are triggered by maliciously crafted files of various kinds. The updated routines in QuickTime 7.5.1 provide additional checking of particular file types to avoid the chance of crashes or arbitrary code execution caused by the following conditions.

3GP: Windows only (integer overflow).

MIDI: Mac and Windows (heap buffer overflow.

MOV: Mac and Windows (heap buffer overflow and integer overflow}.

PICT: Mac and Windows (heap buffer overflow).

QTIF: Mac and Windows (heap buffer overflow and integer overflow).

Since most Mac applications would use QuickTime to handle these file types,  the update is especially important to Mac OS X users. While iTunes (see below) is the main QuickTime application for Windows, the update may be seen as less critical for users of Microsoft's operating systems. However, a number of multimedia titles are based on QuickTime, and it is possible for any of the common multimedia file types to be associated with QuickTime player - either by the user's deliberate action or at an application's behest.

QuickTime 7.1.5 also provides "numerous [unspecified] bug fixes" according to Apple.

Read on for information about the new iTunes, including Vista compatibility.



 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

1