Apple fixes security issues with QuickTime 7.5

By Elinor Mills on 12 June 2008

Apple released QuickTime 7.5 late on Monday, fixing a handful of security issues, including holes that would have allowed someone to run malicious code on a computer and remotely control it.

One of the issues, which would have allowed a maliciously crafted PICT image file to run code, affected computers running Windows Vista and XP SP2.

Four other issues affected Vista and XP SP2, as well as Mac OS X 10.3.9, Mac OS X 10.4.9 through 10.4.11, and Mac OS X 10.5 or later. QuickTime 7.5 fixes a memory corruption issue in the software's handling of AAC-encoded media content; a heap buffer overflow related to PICT images; a stack buffer overflow related to the handling of Indeo video codec content; and a URL issue that was addressed by revealing files in Finder or Windows Explorer rather than launching them.

More information can be found on the Apple website.

Credit for reporting the different security issues was given to Dyon Balding of Secunia Research; Dave Soldera of NGS Software and Jens Alfke; Liam O Murchu of Symantec; an anonymous researcher working with TippingPoint's Zero Day Initiative; and Vinoo Thomas and Rahul Mohandas of McAfee Avert Labs, along with Petko D. Petkov of Gnucitizen working with TippingPoint's Zero Day Initiative.

Two months ago, Apple released QuickTime 7.4.5, which addressed a number of "highly critical" security flaws in the media player.

Topics: video, software, security, quicktime, fix, apple, mac, aac, security issues, 7.5

Related Articles

Comments (1)

  • Patty commented on 15/09/2009 14:54

    Apple, in releasing the security fixes also blocked Safari's ability to play WMP. The original version of Safari with snow leopard would allow WMP to work with FlipMac. Apple clearly did this deliberately and the "faster" version of safari is no longer meaningful. Safari is gone from my set up. Tired of screwing around with retardation. When there are plenty of faster and superior browsers out there. No point in upgrading to Snow Leopard for sure now..If there was any doubt before

Post your own comment

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars within 0..9 & A..F

Submit

Enter your personal information to the left, or sign in with your Facebook account by clicking the button below.

Connect

The Explain Series

Must read