Australian IT JOBS : Sydney IT jobs, UNIX jobs, Linux jobs, Java jobs, ASP jobs Linux.conf.au Linux.conf.au
Technology news and Jobs arrow Information Technology News arrow Apple fixes QuickTime for Java security flaw
Apple fixes QuickTime for Java security flaw PDF Print E-mail
Written by Stephen Withers   
Wednesday, 02 May 2007
Apple has moved quickly to fix the QuickTime for Java vulnerability that earned discoverer Dino Dai Zovi a $10,000 purse from a competition at the recent CanWestSec security conference.

QuickTime 7.1.6 for Mac OS X and Windows overcomes the vulnerability that allowed reading or writing out of the bounds of the allocated heap. This flaw meant a maliciously crafted Java applet could trigger the execution of arbitrary code.

The speedy release of the patch - just a week and a half after the flaw was discovered - underlines its seriousness. A successful exploit meant an attacker could gain control of a computer simply by luring its user to a malicious web page. No other action is required of the user, and there is no outward sign that the attack is taking place. Thus the vulnerability has been likened to the ANI flaw in Windows, which led Microsoft to release a patch outside its normal monthly release cycle.

Other changes in version 7.1.6 include support for Final Cut Studio 2 and timecode and closed captioning display in QuickTime Player.

The Windows version also includes "numerous bug fixes" according to Apple officials.

Mac users may download the update from Apple's web site or via Software Update; Windows users can download it from Apple's web site or via the Apple Software Update utility installed as part of the 'iTunes + QuickTime' package.{moscomment}


Get stories like this delivered daily - FREE - subscribe now
When you subscribe get a 12 months license for LiveProject
Valued at $99 USD


LiveWire - Desktop alerts Download the FREE iTWire desktop alert widget LiveWire - Desktop alerts


Del.icio.us!
 
< Prev   Next >

Latest jobs

Contact , Register , Advertise with iTWire , Links , Register , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging
Industry Releases , Submit your release now , Start submitting to iTWire , How to post video