May 29, 2007 1:51 PM PDT

Apple issues a security update for Quicktime 7.1.6

Today, Apple released a security update for Quicktime 7.1.6, further removing a vulnerability first used by a security researcher in April to win $10,000 and a new Macbook in the "PWN 2 0WN" contest at CanSecWest 2007. This security update complements an earlier bug patch for Quicktime 7.1.6 released by Apple on May 1, 2007. The 1.1Mb Windows Quicktime 7.1.6 update affects users of Windows 2000 SP4, and Windows XP SP2. The 1.4 Mb Mac Quicktime 7.1.6 update affects users of Mac OS X v10.3.9 and Mac OS X v10.4.9.

The vulnerability, as reported in CVE-2007-2175, allows attackers to entice users to a Web site with a maliciously coded Java applet and then run attack code on a compromised machine. The Apple security update places further parameter limitations on QTPointerRef objects in Apple Quicktime Java extensions within the Safari and Firefox browsers, denying these types of attacks. Apple credits security researcher Dino Dai Zovi, working with TippingPoint and the Zero Day Initiative, for his help in resolving this issue.

Recent posts from News Blog
Ixia kicks off competitive upgrade program
Cuba and Venezuela to lay undersea Internet cable
Pubmatic: Online ad prices stay flat
Intel rides high on strong notebook demand
For teens, the future is mobile
Powered by Jive Software
advertisement
  • About News Blog

  • Recent posts on technology, trends, and more.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. Photos: Great Red Spot eats 'Baby'

  2. Pairing your cell with Bluetooth? Buyer beware

  3. Mossberg pans MobileMe amid service outages

  4. Vulnerable to a DNS cache poisoning at home?

  5. Photos: 'Green' graffiti makes paint-free protests

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

advertisement
On TechRepublic: Breaking the law with your computer
Advanced
search
Advanced
search
Visit other CBS Interactive sites