Apple
Six QuickTime vulnerabilities could allow attackers to remotely execute code

Apple releases seven QuickTime fixes

Vulnerabilities affect OS X and Windows versions

Written by Shaun Nichols in California

Apple has patched seven vulnerabilities in the latest version of QuickTime affecting the Windows and MacOS X versions of the media player software.

Each of the vulnerabilities affects users of MacOS 10.3.9, 10.4.9 and 10.5 as well as Windows XP and Vista.

Six of the vulnerabilities could allow attackers to remotely execute code on the targeted machine.

Three of the remote code execution vulnerabilities could be exploited when the user launches a specially-crafted movie file.

Two are exploited by way of malformed Pict files, and one can be targeted by way of a specially-crafted QuickTime VR file.

The update also addresses a flaw in the way QuickTime handles untrusted Java applets. Apple said that this could allow an attacker to run malicious Java code on the user's machine.

The update fixes the issue by preventing untrusted applets from running QuickTime's Java components.

Users can obtain the update through Apple's Software Update utility or the Apple Downloads site.

Tags:

Further reading

Special Report: Apple iPhone

All the latest news on Apple's iPhone   More...

iPhone spanked as a 'mobile toddler'

Apple still has a lot to learn, say analysts   More...

UK flooded with fake iPhones

Counterfeiters target UK market ahead of official launch   More...

Apple QuickTime 7.4.5

Minor upgrade to the video player   More...

Related articles

Apple fixes critical QuickTime flaws

XP, Vista and Mac OS X versions affected   More...

Apple patches two QuickTime holes

Java flaws affect Mac and Windows versions   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Apple patches critical QuickTime flaws

Vulnerabilities could lead to remote code execution   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement