YOUR IT - Technology for you

No. 1 Story

Telstra adds one million mobile services, but Sensis plummets

Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.

read more

Apple plugs QuickTime RTSP hole

Your IT - Home IT

Apple has released a QuickTime update for Mac OS X and Windows that fixes the RTSP vulnerability that surfaced late last month.

A maliciously crafted RTSP movie could cause a buffer overflow, which could be used to either crash the application playing the movie or, more seriously, to execute arbitrary code contained within the stream.

"This update addresses the issue by ensuring that the destination buffer is sized to contain the data," said Apple officials.

The flaw had been exploited to attack Windows systems, though the vulnerability is also present in the Mac OS X version of QuickTime.

The update also fixes a buffer overflow vulnerability in the handling of QTL files, and multiple vulnerabilities in the Flash handler.

"With this update, the Flash media handler in QuickTime is disabled except for a limited number of existing QuickTime movies that are known to be safe," Apple officials said.

It would seem that either the Flash patch is a temporary measure while Apple develops real fixes for the issues raised by various security researchers, or the company has decided to drop the curtain on Flash support in QuickTime, leaving it to Adobe's software.

Separate QuickTime updaters were released for Mac OS X 10.3 Panther, 10.4 Tiger and 10.5 Leopard, as well as one for Windows Vista and XP SP2.

In related news, Apple also released Java Release 6 for Mac OS X 10.4. Security issues feature among the changes delivered by this update.

One Mac-specific issue addressed is the way malicious applets could add or remove items from the user's keychain without prompting, but the update also includes version 1.5.0_13 of Java 2 SE 5.0 (as found in Mac OS X 10.5), which fixes multiple vulnerabilities.

However, Apple's implementation of Java is still behind the curve. The current version of J2SE 5.0 is 1.5.0_14, which includes a long list of bug fixes for _13.

The updates can be obtained via Software Update (Apple Software Update on Windows) or from Apple Downloads .

Loading comments ...

- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more