QuickTime
Apple has plugged a hole in the Windows Vista and XP versions of QuickTime
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Apple patches QuickTime flaw

Windows vulnerability allowed scripted attacks

Shaun Nichols in California, vnunet.com 04 Oct 2007
ADVERTISEMENT

Apple has patched a flaw in QuickTime that could allow for remote attacks.

The fix addresses a vulnerability in the Windows Vista and XP versions of QuickTime, which is commonly installed as a browser plug-in or as a component of iTunes. OS X users are not affected.

Apple said that the problem concerns QuickTime Media Links (QTLs) which are often used to launch media files from browsers.

If a specially crafted QTL is launched, QuickTime can allow access to a command line which could then be used to execute malicious code.

Security researcher Petko D Petkov showed last month how a malformed QTL file could be placed within a web page and disguised as a movie or song file.

When clicked, the links would allow for JavaScript code to run with the privileges of the current user.

The researcher provided several proof-of-concept samples which caused vulnerable machines to display alert boxes, launch arbitrary applications and even shut down.

Although the Apple security notice does not specifically mention the report, a spokesperson confirmed to vnunet.com that the fix addresses the flaw described by Petkov.

Users can obtain the update via the Software Update application or from Apple's support site.

See also:

Apple iPhoneNew trick allows users to reverse killer update  03 Oct 2007
Adobe FlashNew version of player guns for the iPhone crowd  27 Sep 2007
Security firm warns of imminent danger  17 Sep 2007
Apple iPod NanoUpgrades range from new colours to video screens  06 Sep 2007

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
EXCEPTIONAL .NET (ASP / VB / C#) DEVELOPER – SURREY HEDGE FUND My client is a CASH RICH leading Microsoft Technology focused Hedge Fund currently experiencing unrivalled success – they need to bring on fresh ... more >
| JAM Recruitment
Position: Software Developer – Modelling / Simulations Salary: £27-37,000 Location: Luton, Bedford, Milton Keynes Apply to: a.ross@jamrecruitment.co.uk This is an excellent chance to join one of the UK’s leading Defence businesses operating at the forefront ... more >
| JAM Recruitment
Position: Software Engineer – C/C++/GUI/UML Salary: £30-40,000 Location: Leicester Apply to: a.ross@jamjobs.co.uk This is a fabulous opportunity to join a globally recognised organisation working as part of a team taking innovative and cutting edge solutions ... more >
| JAM Recruitment
Position: Embedded Software / Systems Engineer Salary: £25-40,000 Location: Barrow, Cumbria, Carlisle, Lake District Apply to: a.ross@jamrecruitment.co.uk (inc salary expectations, availability and notice period) This is an exciting opportunity to join one of the UKs ... more >
More job opportunities