Flaws Hit QuickTime, iTunes
Moderator: Wiz Feinberg
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Flaws Hit QuickTime, iTunes
Attention Apple users: Step away from reading about MacWorld, put down your iPods and update your QuickTime software now to prevent a hacker from taking over your system.
There are five highly critical flaws in Apple's QuickTime application that affect both Apple and Windows versions, as well as Apple's popular iTunes application.
The flaws all relate to image-handling issues inside of QuickTime. CVE-2005-2340 is described by security firm Secunia as, "a boundary error in the handling of QTIF images [that] can be exploited to cause a heap-based buffer overflow." Such a buffer overflow could allow an attacker to execute arbitrary code.
According to Security firm eEye, QuickTime users aren't the only ones at risk. Users of iTunes are also at risk due to its tight integration with QuickTime and, as such, "all of these security issues are also exploitable via the iTunes software."
Apple has provided an update for QuickTime that patches all the currently publicly disclosed vulnerabilities.
Systems Affected
Apple QuickTime on systems running
* Apple Mac OS X
* Microsoft Windows XP
* Microsoft Windows 2000
Upgrade
Upgrade to QuickTime 7.0.4.
------------------
Bob "Wiz" Feinberg
Moderator of the SGF Computers Forum
<small>Visit my Wiztunes Steel Guitar website at: http://www.wiztunes.com/
or my computer troubleshooting website: Wizcrafts Computer Services,
or my Webmaster Services webpage</small><font size="1" color="#8e236b"><p align="center">[This message was edited by Wiz Feinberg on 12 January 2006 at 09:22 PM.]</p></FONT>
There are five highly critical flaws in Apple's QuickTime application that affect both Apple and Windows versions, as well as Apple's popular iTunes application.
The flaws all relate to image-handling issues inside of QuickTime. CVE-2005-2340 is described by security firm Secunia as, "a boundary error in the handling of QTIF images [that] can be exploited to cause a heap-based buffer overflow." Such a buffer overflow could allow an attacker to execute arbitrary code.
According to Security firm eEye, QuickTime users aren't the only ones at risk. Users of iTunes are also at risk due to its tight integration with QuickTime and, as such, "all of these security issues are also exploitable via the iTunes software."
Apple has provided an update for QuickTime that patches all the currently publicly disclosed vulnerabilities.
Systems Affected
Apple QuickTime on systems running
* Apple Mac OS X
* Microsoft Windows XP
* Microsoft Windows 2000
Upgrade
Upgrade to QuickTime 7.0.4.
------------------
Bob "Wiz" Feinberg
Moderator of the SGF Computers Forum
<small>Visit my Wiztunes Steel Guitar website at: http://www.wiztunes.com/
or my computer troubleshooting website: Wizcrafts Computer Services,
or my Webmaster Services webpage</small><font size="1" color="#8e236b"><p align="center">[This message was edited by Wiz Feinberg on 12 January 2006 at 09:22 PM.]</p></FONT>
-
Anders Brundell
- Posts: 636
- Joined: 2 Nov 1999 1:01 am
- Location: Falun, Sweden
Wiz;
I'm unable to find an update för XP via that link you mention. Could you give more exact info on where to find the actual download?
(I very often get confused and sometimes totally lost when I try to figure out the proper choise on data sites. These sites are certainly not made for us who know very little about pc:s.)
Thanks!
Anders
I'm unable to find an update för XP via that link you mention. Could you give more exact info on where to find the actual download?
(I very often get confused and sometimes totally lost when I try to figure out the proper choise on data sites. These sites are certainly not made for us who know very little about pc:s.)
Thanks!
Anders
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Anders;
Go to this page to download the updated Quicktime for Windows 2000/XP: http://www.apple.com/quicktime/download/win.html
------------------
Bob "Wiz" Feinberg
Moderator of the SGF Computers Forum
<small>Visit my Wiztunes Steel Guitar website at: http://www.wiztunes.com/
or my computer troubleshooting website: Wizcrafts Computer Services,
or my Webmaster Services webpage</small>
Go to this page to download the updated Quicktime for Windows 2000/XP: http://www.apple.com/quicktime/download/win.html
------------------
Bob "Wiz" Feinberg
Moderator of the SGF Computers Forum
<small>Visit my Wiztunes Steel Guitar website at: http://www.wiztunes.com/
or my computer troubleshooting website: Wizcrafts Computer Services,
or my Webmaster Services webpage</small>
-
Anders Brundell
- Posts: 636
- Joined: 2 Nov 1999 1:01 am
- Location: Falun, Sweden
-
Larry Robbins
- Posts: 3522
- Joined: 18 Feb 2003 1:01 am
- Location: Fort Edward, New York
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Today I learned that some Mac and Windows users are experiencing severe problems after upgrading to the Quicktime version listed in my first post. It is a good idea to revist the Apple download page frequently to see if they release another patch to fix the patch that fixes the flaws in the previous patch (wink, wink, nudge, nudge)!
------------------
Bob "Wiz" Feinberg
Moderator of the SGF Computers Forum
<small>Visit my Wiztunes Steel Guitar website at: http://www.wiztunes.com/
or my computer troubleshooting website: Wizcrafts Computer Services,
or my Webmaster Services webpage</small>
------------------
Bob "Wiz" Feinberg
Moderator of the SGF Computers Forum
<small>Visit my Wiztunes Steel Guitar website at: http://www.wiztunes.com/
or my computer troubleshooting website: Wizcrafts Computer Services,
or my Webmaster Services webpage</small>
-
b0b
- Posts: 29079
- Joined: 4 Aug 1998 11:00 pm
- Location: Cloverdale, CA, USA