Text Size

Apple security update fixes QuickTime flaw

updated 04:40 pm EST, Tue January 23, 2007

Apple Security Update

Apple today released Security Update 2007-001, fixing a vulnerability in QuickTime 7.1.3 in various Mac OS X versions that could lead to arbitrary code execution. The buffer overflow exists in QuickTime's handling of RTSP URLs, according to Apple, and is triggered when an unsuspecting user accesses one of these maliciously-crafted addresses. The update addresses the bug -- which was demonstrated in a QTL file that triggers the issue, published earlier this month -- by performing additional validation of RTSP URLs. The vulnerability affects Mac OS X 10.3.9, Mac OS X Server 10.3.9, Mac OS X 10.4.8, Mac OS X Server 10.4.8, and Windows 2000/XP. The update is available for free from Apple's website, and is recommended for all users.

 
Previous Comments

so much for MOAB

01/23, 06:04pm reply

moab's claim was that apple either doesn't respond or is hostile to security claims - is clearly nonsense. this fix is right in line with all the other fixes apple has released, 99% of them with no push from MOAB's tactics.

jpellino

Fresh-Faced Recruit

Joined: Oct 1999

0

um moab was right

01/23, 09:54pm reply

Apple took 23 days to patch this. Microsoft and many other vendors patch critical security flaws (which this is) much more quickly. Microsoft fixed the wmp file vulnerability in 2 days. Most zero day vulnerabilities in Windows have been fixed within 3 days. Apple took 23 days. For a company that supposedly prides themselves on security that's a LOONG time. Consider this: in many companies, if a zero day flaw appears in Word or Internet Explorer, companies restrict usage of those applications to limit exposure. When the Word zero day flaw hit a couple weeks ago, my company temporarily suspended incoming Word attachments until Microsoft fixed the flaw 2 days later. If Macs were widely used, the equivalent policy would have blocked QuickTime access for 23 days.

fubar_this

Fresh-Faced Recruit

Joined: Jul 2006

0

secuirty update problem

01/24, 12:24pm reply

There's one other huge problem with Apple's security updates. If you're not an Administrator on your computer (say, for example, you listened to all those experts who say "to restrict exposure to problems, be a normal user and login as an admin when you have to"), you never get Apple's security updates. Apple doesn't have an "automatically download and install updates" option. The best they've got is "Download and let me know when its ready", but even that only works for admin accounts.

So, with Apple, you either have to stay in touch constantly with security update bulletins, or log in as an admin user once a week just to see if somethings out there.

testudo

Fresh-Faced Recruit

Joined: Aug 2001

0

Re: secuirty update

01/24, 01:07pm reply

testudo, you are probably a typical PC user. What are you talking about? That just means if you are not an administrator you must not touch anything related to the System. You probably don't own that Mac or you are just a kid that have a limited access to it.

If you are the owner, there is no reasons not to be an administrator. There is no "problems" you are talking about, this is not a PC. It is a very secure machine, unless you don't trust yourself or don't know what you are doing.

Gepard

Fresh-Faced Recruit

Joined: Sep 2000

0

Trouble with the update

01/24, 02:12pm reply

After I installed this update this morning, my Griffin PowerMate programmable control k*** stopped responding. I have Griffin Tech Support looking into this issue. Anyone else had problems with this update?

tsmelker

Fresh-Faced Recruit

Joined: Feb 2006

0

wasted breath gepard...

01/24, 04:21pm reply

Turtle boy's a troll.

Z

zac4mac

Senior User

Joined: Oct 1999

0

Troll alert

01/24, 06:20pm reply

... so is Fubar.

tsmelker

Fresh-Faced Recruit

Joined: Feb 2006

0

Popular News