Tuesday, January 23, 2007, 01:00 pm PT (04:00 pm ET)
Apple patches QuickTime exploit published by MoAB websiteApple on Tuesday released a security update for its QuickTime digital media software in response to a vulnerability discovered by security researchers associated with the Month of Apple Bugs website.
The Cupertino-based company said Security Update 2007-001 — its first security update of the 2007 calendar year — plugs an exploit where QuickTime users visiting maliciously crafted websites could fall victim to arbitrary code execution.
"A buffer overflow exists in QuickTime's handling of RTSP URLs. By enticing a user to access a maliciously-crafted RTSP URL, an attacker can trigger the buffer overflow, which may lead to arbitrary code execution," the company said. "A QTL file that triggers this issue has been published on the Month of Apple Bugs web site (MOAB-01-01-2007)."
Apple added that its fix for the issue includes performing additional validation of RTSP URLs.
The security update is available for QuickTime 7.1.3 on Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8, and Windows XP/2000.
The Month of Apple Bugs initiative is an effort by security analysts to improve Apple's Mac OS X operating system, uncovering and finding security flaws in different versions of the company's software and third-party applications.
Apple's security update released Tuesday targets the first of those reported flaws. The Month of Apple Bugs website has since gone on to list 21 additional vulnerabilities in Mac OS X related software, one for each day of the month.
On Topic: General
- Apple's patented iPhone-based CarPlay remote starts cars, performs high-level functions
- Apple responds to Spotlight Suggestions 'backlash,' says personal data collection limited
- Tour Apple Inc's spaceship Campus 2 in extended aerial video
- Editorial: A friendlier Apple Inc now invites media through its Infinite Loop front door
- Apple launches iCloud Photos beta Web client ahead of iOS 8.1 rollout