toggle

AAPL Stock: 431.77 ( 0 )

http://www.macnn.com/articles/07/05/29/quicktime.security.update/

Apple plugs two QuickTime security flaws

updated 04:30 pm EDT, Tue May 29, 2007

 

QuickTime security update


Apple today updated its QuickTime multimedia software by fixing two important security holes that, if left unpatched, could lead to the disclosure of sensitive information or allow a potential attacker to take over a Mac or Windows system running the affected software. The update repairs the implementation issue in QuickTime for Java, which could allow instantiation or manipulation of objects outside the bounds of the allocated heap. In layman's terms, malicious users could use the bug to steal information or take over an unrepaired system. The update performs additional validation of Java applets to prevent arbitrary code execution, and clears memory before allowing it to be used by untrusted Java applets to prevent information theft. [updated]

A security researcher in late April pointed out that Apple had failed to patch two zero-day QuickTime flaws discovered more than a year earlier, but issued a security update on May 1st addressing a critical issue with QuickTime for Java.

Apple last week plugged 17 other security holes in Mac OS X Panther and Tiger, shoring up security concerns in an attempt to make good on the promise of superior Mac security. Various security analysts have warned that Mac users are not immune to security risks, despite popular belief amongst Mac owners themselves. Analysts point to Apple's low market share as one primary reason that the company hasn't come under nearly as much fire from malicious users as Microsoft's Windows system, and predict that the Cupertino-based company will face increasing attacks as it gains more share in the computer market.


by MacNN Staff

Post tools:

TAGS :

 troubleshooting
toggle

Comments

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

Logitech FabricSkin Keyboard Folio for iPad

Since the fourth-generation iPad didn't evolve much over its predecessor, the market for iPad accessories has remained somewhat static ...

Huawei Ascend Mate

The Huawei Ascend Mate is a phone that fits the screen-size gap between the 4 to 5-inch smartphone and the seven-inch or more tablet, ...

MaxUpgrades MaxConnect for 2006-2008 Mac Pro

Nobody outside of Cupertino's privileged bunch knows the future of the Mac Pro line for sure. Despite Apple's reluctance to tell us wh ...

toggle

Most Commented