Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple releases Quicktime 7.1 security update for both OSX and WindowsXP
Apple, Inc. ^ | 1/2 3/2007

Posted on 01/23/2007 9:17:31 PM PST by Swordmaker

About Security Update 2007-001

This document describes Security Update 2007-001, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.

For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.

For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key."

Where possible, CVE IDs are used to reference the vulnerabilities for further information.

To learn about other Security Updates, see "Apple Security Updates."

Security Update 2007-001

  • QuickTime

    CVE-ID: CVE-2007-0015

    Available for: QuickTime 7.1.3 on Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8, Windows XP/2000

    Impact: Visiting malicious websites may lead to arbitrary code execution

    Description: A buffer overflow exists in QuickTime's handling of RTSP URLs. By enticing a user to access a maliciously-crafted RTSP URL, an attacker can trigger the buffer overflow, which may lead to arbitrary code execution. A QTL file that triggers this issue has been published on the Month of Apple Bugs web site (MOAB-01-01-2007). This update addresses the issue by performing additional validation of RTSP URLs.



TOPICS: Business/Economy; Computers/Internet
KEYWORDS:

1 posted on 01/23/2007 9:17:33 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: 1234; 6SJ7; Abundy; Action-America; af_vet_rr; afnamvet; Alexander Rubin; anonymous_user; ...
Security Update for Quicktime - Mac OS X.3.9, OS X.4.x and WindowsXP/2000. PING

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 01/23/2007 9:18:46 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Tomorrow's Wall Street Journal has an interview with the MOAB guys, but notes that the one "showstopper" they found was the QuickTime vulnerability, which is fixed in this update.

Still no viruses, worms or spyware reported in the wild on Mac OS X for over five years.

3 posted on 01/23/2007 10:18:19 PM PST by HAL9000 (Get a Mac - The Ultimate FReeping Machine)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Apple does not disclose, discuss, or confirm security issues



Don't put your head in the sand.. its a dangerous world, deal with it.

4 posted on 01/24/2007 12:16:34 AM PST by Echo Talon
[ Post Reply | Private Reply | To 1 | View Replies]

To: Echo Talon

Well, Gee, Echo, up until the release of Vista, Microsoft's approach to the vast majority of security problems was to let third party companies handle it for them... Now they want to CHARGE their customers additional fees to let Microsoft do it.


5 posted on 01/24/2007 2:29:26 AM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

Sorry Swordmaker, his head is in the sand, he can't hear you.


6 posted on 01/24/2007 3:42:36 AM PST by Shimmer128 (We have only this moment, sparkling like a star in our hand and melting like a snowflake)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

What about Windows Defender that is free?


7 posted on 01/24/2007 12:36:34 PM PST by Echo Talon
[ Post Reply | Private Reply | To 5 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson