Giveaway: Bracketron Case If outdoor adventures are in your future this summer, enter to win a Bracketron Sport Case with Mount Strap from MacNN and keep that iPhone, iPod or other electronic device safe from the elements.      
toggle

AAPL Stock: 443.86 ( -10.88 )

http://www.macnn.com/articles/09/01/21/qt.76.security.fixes/

QuickTime 7.6 fixes 7 security issues

updated 02:30 pm EST, Wed January 21, 2009

 

QT 7.6 security fixes


Apple's QuickTime 7.6 update addresses seven security issues. The first issue involved accessing a maliciously crafted RTSP URL may lead to an unexpected application termination or arbitrary code execution Description: A heap buffer overflow exists in QuickTime's handling of RTSP URLs. Accessing a maliciously crafted RTSP URL may lead to an unexpected application termination or arbitrary code execution. Version 7.6 fixes the issue by performing additional validation of RTSP URLs.

The second resolved issue occurred when viewing a maliciously crafted QTVR movie file, which could cause an unexpected application termination or arbitrary code execution. A heap buffer overflow exists in QuickTime's handling of THKD atoms in QTVR (QuickTime Virtual Reality) movie files. The update fixes the issue by improving bounds checking. The third issue occurred when viewing a maliciously crafted AVI movie file, leading to an unexpected application termination or arbitrary code execution. Again, a heap buffer overflow may occur while processing an AVI movie file. Once again, v7.6 fixes the issue through improved bounds checking.

The fourth and fifth issues are similar to the second and third risks, but involved MPEG-2 video files with MP3 audio content and H.263 encoded movie files. The same bounds checking improvement fixes the MPEG-2 issue, while additional validation of H.263 encoded movie files fixes the fifth issue.

Apple also resolved an issue with QuickTime's handling of Cinepak encoded movie files, which can cause a heap buffer overflow. Viewing a maliciously crafted movie file can lead to an unexpected application termination or arbitrary code execution. QuickTime 7.6 fixes the issue by performing additional validations of movie files. The last issue involves a heap buffer overflow in QuickTime's handling of jpeg atoms in QuickTime movie files, leading to application termination or arbitrary code execution. Improved bounds checking is once again the fix.

The update also features reliability and compatibility improvements. It is recommended for all QuickTime 7 users. The 75.1MB download (via software download) will work with Mac OS X 10.4.9 and higher and Windows Vista, XP SP2 and SP3.

Apple also said that the update improves single-pass H.264 encoding quality, increases playback reliability on Motion JPEG media, has better AAC encoding fidelity and exports more consistently when pulling audio tracks from MPEG video files. Version 7.6 also increases compatibility with iChat and Photo Booth.

Update: QuickTime MPEG-2 Playback Component for Windows has also been updated to add additional validation of MPEG-2 files as a security measure.


by MacNN Staff

Post tools:

TAGS :

 QuickTime, security, software, update, Apple
toggle

Comments

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

Brother HL-3170CDW LED Printer

We've mentioned before that we are far from a paperless society. For now, at least, there are tasks that require a piece of paper for ...

HTC One

It is hard to overstate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming decline ...

Samsung Galaxy S 4

Samsung's new flagship Android smartphone, the Galaxy S 4, faces even stiffer competition than its popular predecessor. With a five-in ...

toggle

Most Commented