Apple QuickTime
Five QuickTime vulnerabilities could allow remote code execution

Apple issues QuickTime 7.5 update

Five security fixes for Mac and Windows versions

Shaun Nichols in California

Apple has issued an important security update for its QuickTime multimedia plug-in.

QuickTime 7.5 includes fixes for five flaws in the Windows XP and Vista versions of the tool, four of which also affect the Mac OS version.

Advertisement

All five vulnerabilities could allow an attacker to remotely execute malicious code on a user's system.

Among the vulnerabilities is a flaw in the PICT component within QuickTime. An attacker could use a specially-crafted image file to cause a memory overflow that would allow for remote code execution. The flaw does not affect Mac OS users.

Each of the four remaining vulnerabilities affect Mac and Windows versions. They include issues in the way QuickTime handles Indeo and AAC files, as well as a second vulnerability in the handling of PICT image files.

The fourth vulnerability concerns a flaw in the handling of URLs within QuickTime Player. An attacker could install and run malicious code when the user launches a specially-crafted QuickTime file.

Apple has fixed the vulnerability by forcing the files to be downloaded to Windows Explorer or the Mac OS desktop rather than automatically launched by QuickTime.

Users can obtain the update automatically through the Software Update component or manually through the Apple Downloads website.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Apple iPhone

Apple unveils iPhone 3G

Jobs does not disappoint at WWDC

Apple iPhone 3G

iPhone 3G is 'no market changer'

New features just keep up with the competition, says analyst

O2 promises UK iPhone 3G on 11 July

Exclusive deals through O2 and Carphone Warehouse

APPLE IPHONE 3G

Does the new 3G version make you more likely to buy an iPhone?

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

a padlock

Microsoft to plug security holes

Microsoft has given advance warning of a number of security...

Nokia handset

Top 10 articles, 10 July 09

No Nokia Android phone, ActiveX attacks and Google enters into...

Can Google beat Microsoft at its own game?

Google's announcement this week that it plans to step into...

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Primary Navigation