QuickTime v 7.4.5 Patches 11 Flaws

QuickTime v 7.4.5 Patches 11 Flaws

Techtree News Staff, Apr 04, 2008 1238 hrs IST

Three of the 11 are exclusive to Windows while the remaining eight are common to both Windows and Mac versions of QuickTime Media Player.

Late yesterday, Apple released QuickTime Media Player version 7.4.5 that patches 11 flaws in the software; three of which are exclusive to the Windows platform while the remaining eight are common to both Windows and Mac versions.

Here's quickly looking at all eleven patches:

  • CVE-2008-1013 fixes a flaw wherein an implementation issue in QuickTime for Java allows untrusted Java applets to de-serialize objects provided by QTJava.


  • CVE-2008-1014 addresses a vulnerability whereby specially-crafted QuickTime movies can automatically open external URLs, which may lead to information disclosure.


  • CVE-2008-1015 fixes another movie file flaw wherein a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution.


  • Patches -- CVE-2008-1016, CVE-2008-1017, and CVE-2008-1018 -- all address flaws wherein downloading malicious movies may lead to code execution and application termination.


  • CVE-2008-1019 fixes a flaw whereby a maliciously crafted PICT image file may lead to an unexpected application termination or arbitrary code execution.


  • CVE-2008-1020, CVE-2008-1021 are applicable exclusively to Windows Vista and XP SP2 and address a vulnerability wherein opening a maliciously crafted PICT image file may lead to unexpected application termination or arbitrary code execution. Apple has credited an anonymous researcher working with TippingPoint's Zero Day Initiative for reporting the flaws.


  • CVE-2008-1022, applicable to both Windows and Mac platforms, deals with a flaw wherein viewing a maliciously crafted QuickTime VR movie file may lead to unexpected application termination or arbitrary code execution. Apple has again credited an anonymous researcher working with TippingPoint's Zero Day Initiative for reporting this flaw.


  • The last patch, the CVE-2008-1023 is available exclusively for the Windows platform and addresses a flaw wherein opening a maliciously crafted PICT image file may lead to unexpected application termination or arbitrary code execution.


  • For users of Mac OS X 10.3, 10.4, and 10.5, they can update their QuickTime software using the operating system's "Software Update" feature in the Apple menu. Windows users meanwhile can download the update by opening QuickTime, and using the 'Update Existing Software' feature available in the help menu. Meanwhile, details of the updates can be found here.



    Write a comment

           (All fields are mandatory.)

    Text Limit = 255 Characters

    Type the characters you see in the picture below.

    #

    Characters are not case sensitive.

    VIEW ALL LATEST

    New Macbook Pro Pic Leaked

    News > Gadgets , October 14, 2008 1213 hrs IST

    Official launch today ...

    Sony Xperia X1 Unboxed

    News > Gadgets , October 14, 2008 1112 hrs IST

    Also gets compared with the HTC Touch Pro ...

    Now, Visit the Forbidden City Virtually

    News > Internet , October 14, 2008 1153 hrs IST

    Take a tour of the world renowned palace for free ...

    Apple Dumping Intel for Nvidia?

    News > Gadgets , October 14, 2008 1236 hrs IST

    Speculations run rife before the launch ...

    New Chatbot Closer To Passing Turing AI Test

    News > Software , October 14, 2008 0847 hrs IST

    Almost as annoying as a human ...

     

    USER REVIEWS

    MOST POPULAR NEWS

    Hide
    News

    Could A DVR Save Your Marriage?

    News | Consumer Electronics | 04 Sep 2008

    ...Or should you stick to your shrink?

    News

    Firefox Counters Chrome's Speed Test

    News | Internet | 04 Sep 2008

    According to Mozilla's SunSpider test, Firefox 3.1 is 28% faster than Chrome on ...

    News

    Nokia N96 for Rs. 40,000?

    News | Telecom | 04 Sep 2008

    False alarm everyone... We have learnt from Nokia that the N96 will be priced be...

    MOST POPULAR REVIEWS

    Hide

    MOST POPULAR GAMES

    Hide

    MOST POPULAR DOWNLOADS

    Hide
    Downloads

    Forbidden.exe

    Downloads | Games | 02 Sep 2008

    Downloads

    md5deep

    Downloads | System Tools | 04 Sep 2008

    Downloads

    RivaTuner

    Downloads | System Tools | 03 Sep 2008