Please wait while the page is being loaded Skip this advertisement >
Monday | 8 September, 2008
ARN
After attacks, Apple fixes QuickTime bug
Apple has patched a critical security flaw in QuickTime that was being exploited by attackers.
Robert McMillan (IDG News Service) 14 December, 2007 12:19:30

Related Stories
  • +

    Life on the EEEdge: Daily life with Asus' tiny laptop 04 January, 2008 07:15:21

    6 annoying things (and 3 great ones) about Asus' ultraportable
    Like many gearheads, I've owned a lot of portable computers over the years -- and I've wanted to replace every last one with a smaller, sleeker upgrade, from the "luggable" Apple IIc onward. But most of those upgrades have left me disappointed: with the lack of software; with cheap, hard-to-use interfaces; and with "optional" add-ons that were in fact very much necessary to make the machine useful.
  • +

    Apple patches QuickTime, iPhone, iPod bugs 16 January, 2008 08:31:24

    But last week's critical QuickTime RTSP flaw not fixed, says researcher
    Just hours after Apple's CEO Steve Jobs touted iTunes and the iPhone, the company plugged four security holes in QuickTime -- iTunes' media-player sidekick -- and fixed three flaws in both the iPhone and its iPod Touch cousin.
  • +

    IT people, places and things that matter 24 December, 2007 07:23:06

    For their ability to draw your attention, these 10 people, places and things stand out as newsmakers that matter
    What makes a top newsmaker? Sometimes a company generates lots of buzz by doing particularly innovative things, or someone with a catalyzing personality gains notoriety. Other times a hot new product or a spectacular disaster gets the attention of the masses.
  • +

    Another month, another monster Apple security update 19 December, 2007 08:16:41

    42 fixes for Leopard, Tiger, Safari for Windows bring year's total to 196
    Apple on Monday matched the patch count of last month's massive update, fixing 41 vulnerabilities in Mac OS X and updating the beta of its Windows browser to fix another.
  • +

    True crime: The botnet barons 04 January, 2008 07:03:57

    Two weeks ago, the feds revealed the names of eight people who had used botnets to engage in nefarious activity. Here are their stories
    When federal agents announced on November 29 that they'd indicted or convicted eight individuals accused of using botnets (networks of computers infected with Trojan horse applications) to engage in criminal activity, the press release barely explained the nature and extent of the men's crimes -- or the investigations that led to arrests in an operation the FBI and other law enforcement agencies have termed Bot Roast II.
Additional Resources
ARN Library

Newsletter Subscription

Sign up for our ARN newsletters!
The premier provider of daily news to the IT channel, covering business, technology, products, and services.
RSS Feeds

Apple has released a new security patch for QuickTime, its eighth update this year for the media player software.

The update addresses three critical security holes in QuickTime, including a vulnerability that has been used in attacks by online criminals.

The most critical of the flaws lies in QuickTime's implementation of the Real Time Streaming Protocol (RTSP), used to play audio and video over the Internet. The flaw was made public Nov. 23, and in early December attackers began exploiting the flaw in online attacks. By tricking victims into visiting a malicious Web site that exploited the flaw, hackers were able to install malicious software on the victims' PCs.

To date, these attacks have targeted Windows-based systems, but security experts say that Mac OS X users are also at risk to the vulnerability. Apple issued patches for both Windows and Mac OS X users on Thursday.

The second critical vulnerability, which had apparently not been publicly disclosed, has to do with a flaw in the QuickTime Media Link (QTL) file format used by the media player. Security researchers have recently been looking at the way QuickTime works with these files as a potential source of new bugs.

Apple also patched a handful of similar bugs in the way that QuickTime handles Adobe's Flash media format. The most serious of these flaws could let attackers run unauthorized software on the computer, much as the RTSP bug does, Apple said.

With security researchers paying special attention to media format bugs, Apple has had to patch QuickTime frequently this year. Some of these updates have come just weeks apart. Apple last patched QuickTime on Nov. 5.

Market Place

ARN Member Login

 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

NAB works with Avanade® to leverage Microsoft® Windows Server® 2008 for its branch offices

In 2007, Avanade helped the National Australia Bank use Windows Server 2008 to simplify deployment, maximise the efficiency of their low-bandwidth wide area network and consolidate its IT infrastructure.

Sponsored Links