No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

Adoption of cloud computing has reached a tipping point  - but don’t expect legacy...
In yet another blow to the Facebook IPO this week, following the withdrawal of...
Recruitment technology and social media have played a significant role in growing business in...
Users of the Citrix GoToAssist remote support product have clocked up 50 million sessions....
Practical, affordable and long life fuel cells have been hyped up every now and...

Apple fixes QuickTime for Java security flaw

Your IT - Home IT

Apple has moved quickly to fix the QuickTime for Java vulnerability that earned discoverer Dino Dai Zovi a $10,000 purse from a competition at the recent CanWestSec security conference.

QuickTime 7.1.6 for Mac OS X and Windows overcomes the vulnerability that allowed reading or writing out of the bounds of the allocated heap. This flaw meant a maliciously crafted Java applet could trigger the execution of arbitrary code.

The speedy release of the patch - just a week and a half after the flaw was discovered - underlines its seriousness. A successful exploit meant an attacker could gain control of a computer simply by luring its user to a malicious web page. No other action is required of the user, and there is no outward sign that the attack is taking place. Thus the vulnerability has been likened to the ANI flaw in Windows, which led Microsoft to release a patch outside its normal monthly release cycle.

Other changes in version 7.1.6 include support for Final Cut Studio 2 and timecode and closed captioning display in QuickTime Player.

The Windows version also includes "numerous bug fixes" according to Apple officials.

Mac users may download the update from Apple's web site or via Software Update; Windows users can download it from Apple's web site or via the Apple Software Update utility installed as part of the 'iTunes + QuickTime' package.