News, info, and opinion by Mac users, for Mac users.

November 6, 2007

security

QuickTime 7.3 swats several bugs dead

Posted Nov. 6, ’07, 9:01 AM PT by Dan Moren
Category | Security

QuickTime SecurityWe rib Apple—good-naturedly, for the most part—about the brevity of their documentation on software updates.

That’s all.

Kidding, kidding. Despite their tight-lipped nature, Apple’s pretty good when it comes to security content. So while the description of yesterday’s QuickTime 7.3 release didn’t go into much beyond “bug fixes,” there’s an entirely separate document about all the security vulnerabilities fixed in the update. Seven holes were patched, six of which could potentially have resulted in arbitrary code execution by using maliciously crafted data files. The seventh hole was related to QuickTime for Java and allowed untrusted Java applets to obtain elevated privileges and execute code.

Yowza. Those are certainly some serious bugs, and it’s good to see Apple’s patched them up. I for one, feel a lot safer now—just remember to stay away from, ahem, those questionable sites.

[via Macworld]


Leave a comment

 




Visit other IDG sites: