| Apple patches for QuickTime for Windows |
|
| by Stephen Withers | |
| Thursday, 04 October 2007 | |
Apple has released a security update for QuickTime 7.2 for Windows, protecting against a vulnerability that allowed maliciously crafted QTL files.Featured Whitepaper
5 Best Practices for Smartphone Support
The flaw is that the ability to include JavaScript in a QTL file could be exploited to cause the execution of arbitrary code by passing command line arguments to another application. The issue was identified by Petko Petkov in September 2006, but remained unaddressed until he published a proof of concept exploit on September 12, 2007 Firefox 2.0.0.7 was released to guard against such exploits being carried out via that browser, but it seems that Apple's patch addresses the issue at a lower level, preventing other applications from being used as vectors. Security Update for QuickTime 7.2 for Windows can be obtained from Apple Downlaods http://www.apple.com/support/downloads/ or via the Apple Software Update utility. The Mac OS X version of QuickTime is not affected by this issue. |
| < Next story in category | Previous story in the category > |
|---|






Tags




