internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Apple's QuickTime Gets Timely Update
QuickTime 7.5 Release Addresses New Security Vulnerabilities
Sean Michael Kerner

Hidden behind the massive hype that was the iPhone 3G launch is the fact that Apple's critical QuickTime software, which enables multimedia playback and iTunes, remains software under siege.

The QuickTime 7.5 update fixes five issues that could potentially leave users at risk from attackers.

Though Apple is patching QuickTime yet again, at least one of the security firms responsible for discovering some of the QuickTime flaws believes that Apple is moving some of the updates in a timely fashion.

Four of the issues affect QuickTime running on both Mac and Windows, while one issue is unique to Windows.

The Windows-only QuickTime 7.5 patch deals with a flaw in how the media software handles PICT images, which is identified as CVE-2008-1581. The flaw could have let an attacker execute arbitrary code or trigger an application crash.

A separate issue regarding PICT handling affects both Windows and Mac versions of QuickTime, and Apple identifies it as CVE-2008-1583.

Another flaw relates to how QuickTime handles the AAC format, which is the default for iTunes content. This problem could lead to a crash or arbitrary code execution.

3Com's Tipping Point division is credited with reporting the final two flaws fixed in QuickTime 7.5. The patch for the issue CVE-2008-1584 fixes a flaw in how QuickTime handles Indeo video media content.

The other problem Tipping Point identified is CVE-2008-1585, which is a URL-handling flaw.

"A URL-handling issue exists in QuickTime's handling of file: URLs," Apple's advisory states. "This may allow arbitrary applications and files to be launched when a user plays maliciously crafted QuickTime content in QuickTime Player. This update addresses the issue by revealing files in Finder or Windows Explorer rather than launching them."

The QuickTime 7.5 update follows the QuickTime 7.4.5 update from April, which fixed 11 issues.

Apple has been the subject of scrutiny by security researchers, including Tipping Point. However, Cody Pierce, security researcher for TippingPoint's DVLabs team, noted that in general Apple has been fairly responsive to issues the group raised.

"The first vulnerability listed, CVE-2008-1584, was reported on 2008-02-07, which is a little longer than desired but in general acceptable," Pierce told InternetNews.com.

"As for CVE-2008-1585, Apple was very timely in correcting an issue taking a little over a month to respond," Pierce added. "It is good to see vendors taking the effort to protect their customers quickly — I hope the trend continues."

News courtesy of internetnews.com

June 11, 2008

Download QuickTime for Windows!Download

View All Video / Multimedia Products

Contents:
1. QuickTime 7.5 Release Addresses New Security Vulnerabilities


Additional Articles:

  • Apple Readies Next-Gen MPEG-4 Part 10
  • Apple Patches QuickTime Flaw
  • Apple Update Patches QuickTime
  • Flaws Hit QuickTime, iTunes
  • QuickTime Exploit Greets 'Month of Apple Bugs'
  • Apple Fixes QuickTime Image Flaws
  • Apple Aims to Patch Persistent QuickTime Hole
  • US-CERT Warns of Unpatched QuickTime Flaw
  • Apple Secures QuickTime
  • More Trouble for QuickTime
  • Apple Fixes a Quartet of QuickTime Flaws


  • internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info

    Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Whitepapers and eBooks

    Symantec Whitepaper: Converging System and Data Protection for Complete Disaster Recovery
    Intel Whitepaper: Comparing Two- and Four-Socket Platforms for Server Virtualization
    IBM Solutions Brief: Go Green With IBM System xTM And Intel
    HP eBook: Simplifying SQL Server Management
    IBM Contest: Are You the Next Superstar? Join the "Search for the XML Superstar" Contest to Find Out
    Intel PDF: Quad-Core Impacts More Than the Data Center
    Intel PDF: Virtualization Delivers Data Center Efficiency
    Go Parallel Article: PDC 2008 in Review
    Avaya Article: Communication-Enabled Mashups: Empowering Both Business Owners and IT
    Intel Whitepaper: Building a Real-World Model to Assess Virtualization Platforms
    PDF: Intel Centrino Duo Processor Technology with Intel Core2 Duo Processor
    Microsoft Article: Build and Run Virtual Machines with Hyper-V Server 2008
      Go Parallel Article: Q&A with a TBB Junkie
    IBM Whitepaper: Innovative Collaboration to Advance Your Business
    Internet.com eBook: Real Life Rails
    IBM eBook: The Pros and Cons of Outsourcing
    Internet.com eBook: Best Practices for Developing a Web Site
    IBM CXO Whitepaper: The 2008 Global CEO Study "The Enterprise of the Future"
    Avaya Article: Call Control XML in Action - A CCXML Auto Attendant
    IBM CXO Whitepaper: Unlocking the DNA of the Adaptable Workforce--The Global Human Capital Study 2008
    Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
    Symantec Whitepaper: Comprehensive Backup and Recovery of VMware Virtual Infrastructure
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES