No. 1 Story

Technology reinforces generation gap

If you believe that technology could be bridging the generation gap, think again. According to Deloitte’s first State of the Media report it’s as stark as ever.

read more

Related Articles

Adoption of cloud computing has reached a tipping point  - but don’t expect legacy...
In yet another blow to the Facebook IPO this week, following the withdrawal of...
Recruitment technology and social media have played a significant role in growing business in...
It's no longer unusual for a household or small business to use a mixed...
D-Link's latest wireless router is claimed to be three times faster than Wireless N...

Multiple Apple updates deliver security patches as well as new features

Your IT - Home IT

Microsoft wasn't the only company to have a Patch Tuesday this month. Updates from Apple include security fixes for widely used software including QuickTime and iTunes. As in the Windows updates, several of the issues addressed by Apple concern malformed media files.

Apple released new versions of iTunes, QuickTime and Front Row for Mac OS X, and of iTunes, QuickTime, MobileMe Control Panel, and Bonjour for Windows.

From a security perspective, the change in iTunes 8.0 for Mac was primarily cosmetic: a warning dialog has been changed to clarify the effect of unblocking iTunes Music Sharing in the firewall.

The fix in the Windows version involves an unspecified third-party driver and an integer overflow that can be exploited by a local user to gain system privileges.

If you're in a situation where local privilege escalations are a concern, you probably don't let people install or run iTunes.

QuickTime is even more widely used, for example by cross-platform multimedia packages. Version 7.5.5 fixes several Windows-specific flaws that can be exploited with maliciously crafted Indeo or PICT files.

Cross-platform flaws can be exploited with maliciously crafted QTVR, H.264, PICT or movie files.

All of the QuickTime flaws can result in the failure of an application; all but one have the potential to allow the execution of arbitrary code.

Bonjour for Windows 1.0.5 provides better checking of DNS labels to avoid a denial of service attack using maliciously crafted .local domain names, and applies source port and transaction ID randomisation to reduce the risk of spoofed information being delivered for unicast DNS queries.

Apple notes "there are no known applications that use the Bonjour APIs for unicast DNS hostname resolution."

What else is new? Find out on page two.