April 8, 2008 8:37 AM PDT

Apple issues QuickTime updates

by Dawn Kawamoto
  • Font size
  • Print
  • 19 comments

Apple has released a QuickTime security update to address "highly critical" security flaws in its media player that could allow malicious attackers to take control of a user's system.

The security flaws affect QuickTime 7 versions running on the Mac OS X and Windows. Users are advised to update to QuickTime 7.4.5, according to an Apple advisory issued Wednesday.

Apple issued 11 security updates designed to prevent malicious attackers from disclosing users' sensitive information, executing arbitrary code, or causing an application to suddenly crash.

Users can be hit with such evil dealings when visiting a Web site rigged with malicious Java applets, view a tampered movie file or open a malicious PICT image file, according to the advisory.

Lovely, eh?

For those who want to delve deeper into the nitty gritty details of the vulnerabilities check out TippingPoint Zero Day Initiative, which discovered some of these flaws, as well as security researcher Secunia, which lists all 11 updates.

Dawn Kawamoto covers enterprise security and financial news relating to technology for CNET News. E-mail Dawn.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register) (19 Comments)
  • prev
  • 1
  • next
Wouldn't it be lovely
by Lee in San Diego April 8, 2008 9:51 AM PDT
"Lovely, eh?'

Lovely that Apple issued a fix?
Reply to this comment
Wouldn't it be lovely
by Lee in San Diego April 8, 2008 9:51 AM PDT
"Lovely, eh?'

Lovely that Apple issued a fix?
Reply to this comment
This is old news from last week
by ecotopian--2008 April 8, 2008 10:12 AM PDT
A more appropriate headline would have been, "Don't forget to
apply Apple's recent Quicktime Updates!" The headline, "Apple
issues QuickTime updates," implies that there is a new update.
Reply to this comment
This is old news from last week
by ecotopian--2008 April 8, 2008 10:12 AM PDT
A more appropriate headline would have been, "Don't forget to
apply Apple's recent Quicktime Updates!" The headline, "Apple
issues QuickTime updates," implies that there is a new update.
Reply to this comment
anti-hacking measures
by kool_skatkat April 8, 2008 10:18 AM PDT
I heard from other source that it also has anti-hacking measure? Any of it true, none of it mentioned here.

http://www.flickr.com/photos/kool_skatkat/
Reply to this comment
True, according to E-Week
by calpundit April 8, 2008 11:23 AM PDT
There was a story in E-Week about it.

http://www.eweek.com/c/a/Security/Apple-Adds-AntiHacker-
Features-to-QuickTime/

I don't understand the technology aspect, but in the story Apple
even gets props from one of the guys who's made breaking into
Quicktime a personal crusade.
anti-hacking measures
by kool_skatkat April 8, 2008 10:18 AM PDT
I heard from other source that it also has anti-hacking measure? Any of it true, none of it mentioned here.

http://www.flickr.com/photos/kool_skatkat/
Reply to this comment
True, according to E-Week
by calpundit April 8, 2008 11:23 AM PDT
There was a story in E-Week about it.

http://www.eweek.com/c/a/Security/Apple-Adds-AntiHacker-
Features-to-QuickTime/

I don't understand the technology aspect, but in the story Apple
even gets props from one of the guys who's made breaking into
Quicktime a personal crusade.
Being serious...
by jelloburn April 8, 2008 10:34 AM PDT
who actually uses PICT files anymore? I'm not saying that the non-
usage of PICT files is an excuse for Apple, but it got me wondering
if anybody uses the format anymore.

Also, I agree with the other post. I actually ran software update
thinking there was a new update. Timeliness is always appreciated
c|net
Reply to this comment
Picts
by Lee in San Diego April 8, 2008 10:43 AM PDT
"who actually uses PICT files anymore?"

If I remember my history studies, the Picts pretty much got
absorbed in with the Scots :)

Seriously the support for PICT images is just a legacy thing from
the old Mac days. Schools and such may still have clip art in PICT
format. Lovely eh?
Being serious...
by jelloburn April 8, 2008 10:34 AM PDT
who actually uses PICT files anymore? I'm not saying that the non-
usage of PICT files is an excuse for Apple, but it got me wondering
if anybody uses the format anymore.

Also, I agree with the other post. I actually ran software update
thinking there was a new update. Timeliness is always appreciated
c|net
Reply to this comment
Picts
by Lee in San Diego April 8, 2008 10:43 AM PDT
"who actually uses PICT files anymore?"

If I remember my history studies, the Picts pretty much got
absorbed in with the Scots :)

Seriously the support for PICT images is just a legacy thing from
the old Mac days. Schools and such may still have clip art in PICT
format. Lovely eh?
cute!
by Dalkorian April 8, 2008 3:04 PM PDT
Here I was reading this article and thinking Apple was really
quick patching the exploit uncovered in CanSecWest's
competition (all we know for sure is Safari was used to connect
to the exploit site, but it could easily have been a QuickTime
flaw used). Turns out this was an update released a week ago
(VERY unlikely to address the recent exploit).

At least it prompted me to check again and verify that I'm up to
date.
Reply to this comment
cute!
by Dalkorian April 8, 2008 3:04 PM PDT
Here I was reading this article and thinking Apple was really
quick patching the exploit uncovered in CanSecWest's
competition (all we know for sure is Safari was used to connect
to the exploit site, but it could easily have been a QuickTime
flaw used). Turns out this was an update released a week ago
(VERY unlikely to address the recent exploit).

At least it prompted me to check again and verify that I'm up to
date.
Reply to this comment
Really a QT update??
by Daler April 9, 2008 1:46 PM PDT
Is it possible there really wasn't a QuickTime update and it really was another chance for Apple to push Safari on everyone? Doh!
Reply to this comment
WTF?
by Lee in San Diego April 9, 2008 2:14 PM PDT
n/c
Really a QT update??
by Daler April 9, 2008 1:46 PM PDT
Is it possible there really wasn't a QuickTime update and it really was another chance for Apple to push Safari on everyone? Doh!
Reply to this comment
WTF?
by Lee in San Diego April 9, 2008 2:14 PM PDT
n/c
by paulanewton September 20, 2008 11:12 AM PDT
I lost my QuickTime and Safari. I went back to September 19, 2008 to see if it they were deleted by a mistake and for some reason I can not retrieve them. Help!
Reply to this comment
(19 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right