Apple fixes zero-day QuickTime flaw

Apple products and Mac operating systems. Including discussions on Virtual PC for Mac, Parallels Desktop for Mac, all Apple hardware and everything relating to Mac!
(MacCentre701)

Moderator: Mandrake

Apple fixes zero-day QuickTime flaw

Postby Antony » Wed 24 Jan, 2007 6:10 am

Image

About 23 days after the public releasing of QuickTime zero-day flaw by "Month of the Apple Bugs", Apple released Security Update 2007-001 for both Mac OS X v10.4 and 10.3 and addressed this issue.

Security Update 2007-001 is recommended for all users and improves the security of the following components:

QuickTime



To download the Security Update, please visit
Security Update 2007-001 (Universal)
Security Update 2007-001 (for Mac OS X 10.3.x "Panther")


Security Update 2007-001

QuickTime

CVE-ID: CVE-2007-0015

Available for: QuickTime 7.1.3 on Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8, Windows XP/2000

Impact: Visiting malicious websites may lead to arbitrary code execution

Description: A buffer overflow exists in QuickTime's handling of RTSP URLs. By enticing a user to access a maliciously-crafted RTSP URL, an attacker can trigger the buffer overflow, which may lead to arbitrary code execution. A QTL file that triggers this issue has been published on the Month of Apple Bugs web site (MOAB-01-01-2007). This update addresses the issue by performing additional validation of RTSP URLs.
UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.1) Gecko/20061204 Firefox/2.0.0.1
User avatar
Antony
diamond member
diamond member
 
Posts: 14510
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia

Return to Mac OS and Apple

Who is online

Registered users: Google [Bot], Yahoo [Bot]