This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Quicktime mulitple Vulns - upgrade available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1329
Last Updated: 2006-05-12 00:18:50 UTC
"Apple released a Quicktime upgrade to version 7.1 that fixes a number of vulnerabilities in the Quicktime viewer. Normally I'd like suggest to read the release notes* for details, but they are typically thin in explaining what's been fixed and/or otherwise changed.
Basically viewing crafted images:
* JPEGs [CVE-2006-1458],
* Flashpix [CVE-2006-1249],
* PICT [CVE-2006-1453, CVE-2006-1454],
* BMP [CVE-2006-2238]
and movies:
* Quicktime [CVE-2006-1459, CVE-2006-1460]
* Flash [CVE-2006-1461]
* H.264 [CVE-2006-1462, CVE-2006-1463],
* MPEG-4 [CVE-2006-1464]
* AVI [CVE-2006-1465]
…can lead to arbitrary code execution.
The fixed version is available for both OS X and Windows. The best about it all is that at least we don't get the implicit insults we should only visit trusted websites. Without more information the only option is not to use quicktime or upgrade…"
* http://docs.info.apple.com/article.html?artnum=303752

>>> http://www.apple.com/quicktime/download/standalone.html

:ph34r:
FYI…

- http://secunia.com/advisories/20069/
Release Date: 2006-05-12
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Vendor Patch
Software: Apple Quicktime 4.x, Apple Quicktime 5.x, Apple Quicktime 6.x, Apple QuickTime 7.x
Description:
Multiple vulnerabilities have been reported in QuickTime, which can be exploited by malicious people to compromise a user's system…
Solution: Update to version 7.1…"

>>> http://www.apple.com/quicktime/download/standalone.html

:ph34r: