Apple fixes security issues with QuickTime 7.5

By Elinor Mills on 12 June 2008

Tags: aac | apple | fix | mac | quicktime | security | software | video | security issues | 7.5

Apple released QuickTime 7.5 late on Monday, fixing a handful of security issues, including holes that would have allowed someone to run malicious code on a computer and remotely control it.

One of the issues, which would have allowed a maliciously crafted PICT image file to run code, affected computers running Windows Vista and XP SP2.

Four other issues affected Vista and XP SP2, as well as Mac OS X 10.3.9, Mac OS X 10.4.9 through 10.4.11, and Mac OS X 10.5 or later. QuickTime 7.5 fixes a memory corruption issue in the software's handling of AAC-encoded media content; a heap buffer overflow related to PICT images; a stack buffer overflow related to the handling of Indeo video codec content; and a URL issue that was addressed by revealing files in Finder or Windows Explorer rather than launching them.

More information can be found on the Apple website.

Credit for reporting the different security issues was given to Dyon Balding of Secunia Research; Dave Soldera of NGS Software and Jens Alfke; Liam O Murchu of Symantec; an anonymous researcher working with TippingPoint's Zero Day Initiative; and Vinoo Thomas and Rahul Mohandas of McAfee Avert Labs, along with Petko D. Petkov of Gnucitizen working with TippingPoint's Zero Day Initiative.

Two months ago, Apple released QuickTime 7.4.5, which addressed a number of "highly critical" security flaws in the media player.

Like this article? Click below to send it to your mobile for free!

Be the first to comment on this article!

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • ZoneAlarm Internet Security Suite 2009

  • PC Tools to be poor man's Norton

  • Symantec wants another chance

  • Olympics cybersecurity

  • New worm targets Facebook, MySpace

  • The Mac uninstallers

  • First iPhone antivirus app released

  • Free Speed: Make your Mac faster

  • Apple fixes security issues with QuickTime 7.5

More articles »

Find the right software

Brand
  • Multiple options can be selected

    The Explain Series

    • ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security 2009 provides top-notch security protection that is light on system resources, allowing you to work unencumbered.

    • Ad-Aware 2008

      Ad-Aware 2008

      This year's update to user favourite Ad-Aware is quite a significant overhaul, and the result is faster scan times and a new interface.

    • AVG Internet Security 8.0

      AVG Internet Security 8.0

      AVG Internet Security 8.0 provides strong protection against malicious Web sites, but its full-system scans sometimes tax system resources and produce false positives.

    • Sunbelt CounterSpy 2.0

      Sunbelt CounterSpy 2.0

      In its first appearance, CounterSpy was the only antispyware product that correctly identified every piece of spyware in our current active-detection test.

    • Ad-Aware 2007

      Ad-Aware 2007

      Lavasoft Ad-Aware 2007 came in dead last in our CNET antispyware testing. Ad-Aware failed to detect half of the test spyware, and unlike nine out of the 10 other antispyware apps we reviewed in December 2007, left behind traces for all but one spyware.

    More reviews »

    Membership benefits

    Create wishlists

    Create wishlists

    See a product on CNET.com.au that you want? Add it to your wishlist and send a hint to your friends and family. Sign up for a free CNET.com.au membership now!