Please help us by taking our survey
macnn/ipodnn

12/13/2007, 6:40pm, EST

Thursday, December 13th

QuickTime 7.3.1, GarageBand 4.1.1 released

Apple today issued security updates to its QuickTime 7.3.1 software (Panther, Tiger, Leopard, Windows) for Mac OS X 10.3.9 Panther, 10.4.9 Tiger, 10.5 Leopard, and Windows Vista/XP SP2 that bolsters security. The Cupertino-based company also enhanced its GarageBand audio software. GarageBand 4.1.1 features better overall stability and fixes to issues with file export to iPhone. [updated]

Specific security issues addressed in Apple's latest QuickTime update follow:

Viewing a maliciously crafted RTSP movie may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow exists in QuickTime's handling of Real Time Streaming Protocol (RTSP) headers. By enticing a user to view a maliciously crafted RTSP movie, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue by ensuring that the destination buffer is sized to contain the data. This issue affects Mac OS X 10.3.9, Mac OS X 10.4.9 or later, Mac OS X 10.5 or later, and Windows Vista/XP SP2.

Viewing a maliciously crafted QTL file may lead to an unexpected application termination or arbitrary code execution Description: A heap buffer overflow exists in QuickTime's handling of QTL files. By enticing a user to view a maliciously crafted QTL file, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking. This issue affects Mac OS X 10.3.9, Mac OS X 10.4.9 or later, Mac OS X 10.5 or later, and Windows Vista/XP SP2

Multiple vulnerabilities in QuickTime's Flash media handler Description: Multiple vulnerabilities exist in QuickTime's Flash media handler, the most serious of which may lead to arbitrary code execution. With this update, the Flash media handler in QuickTime is disabled except for a limited number of existing QuickTime movies that are known to be safe. Credit to Tom Ferris of Adobe Secure Software Engineering Team (ASSET), Mike Price of McAfee Avert Labs, and security researchers Lionel d'Hauenens & Brian Mariani of Syseclabs for reporting this issue. This issue affects Mac OS X 10.3.9, Mac OS X 10.4.9 or later, Mac OS X 10.5 or later, and Windows Vista/XP SP2


Filed under: security, software
Other story tags: QuickTime, system updates, GarageBand

, , 1 comment, del.icio.us, slashdot, digg, buzz


1 comment
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
yoh uh golly gee
0
12/13, 10:34pm, EST
Wasn't this the end-of-the-world-most-awful-civilization-ending thing we were just hearing about from some so-called "security" consultants just last week?

Let's see- 2 people were affected (they both work for the security firm) and now the problem is gone.

A better headline would be: APPLE FIXES ALLEGED SECURITY ISSUE QUICKLY, WINDOWS STILL PLAGUED BY HUNDREDS OF FLAWS WITH NO FIX FROM MICROSOFT FORTHCOMING

Doofuses.
Fresh-Faced Recruit
Joined Nov 2005
User is offline
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

Buy from the Apple Store The Apple Store: Get great deals on the iPod video, iPod Radio Remote, Refurbished iPods starting at $79, iPod shuffle or iPod nano with free engraving, other iPod accessories for the road, or education discounts on iPods.

Convert PDF to Word: Easily Convert PDF to Word Doc, Excel, and More. Fast and Accurate. No Registration Trial

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

NewsGator Enterprise RSS: Improve Corporate Communication via Web 2.0, RSS, and Social Computing.

Get an IT Degree Online: Get solid credentials. Take your hobby to the next level. Adult Programs. Affordable.


Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.