440Forums  |  MacMusic.org  |  PcMusic.org  |  440tv  |  Zicos  |  AudioLexic
update   {key13}


QuickTime 7.4.1 Fixes Zero-Day Vulnerability

TidBITS

Thursday February 7, 2008. 01:32 AM
TidBITS

Apple has released QuickTime 7.4.1, a critical security update all users should apply immediately. It is available via Software Update and as a direct download for Leopard, Tiger, Panther, and Windows systems. This update patches a month-old zero-day vulnerability in the QuickTime streaming protocol (RTSP) that could allow an attacker to take over your computer if you visit a malicious Web site or receive an email with a malicious link. In security parlance, we call this "remote execution of arbitrary code," using a vulnerability for which no patch exists (the "zero-day" part). This is similar to a previous vulnerability in RTSP that Apple patched in the QuickTime 7.3.1 update (see "QuickTime 7.3.1 Fixes RTSP Vulnerability," 2007-12-14). As usual, release notes are a sparse "addresses security issues and improves compatibility with third-party applications." A separate security note provides more details, but the security information isn't even referenced by the release notes on the download page, although they do appear on the security updates page. Since this vulnerability has been in the wild with sample exploits for nearly a month, it is absolutely critical to apply the patch as quickly as possible. Copyright © 2008 Rich Mogull. TidBITS is copyright © 2008 TidBITS Publishing Inc. If you're reading this article on a Web site other than TidBITS.com, please let us know, because if it was republished without attribution, by a commercial site, or in modified form, it violates our Creative Commons License. Yojimbo 1.5 from Bare Bones Software: Your effortless, reliableinformation organizer for Mac OS X. It will change your life,without changing the way you work. Download the demo or buy ittoday!   ...
Apple released QuickTime 7.4.1 critical security update users should apply immediately. QuickTime 7.4.1 Fixes Zero-Day Vulnerability
QuickTime 7.4.1 Fixes Zero-Day Vulnerability Read more at TidBITS
db.tidbits.com/article/9450?rss

 

 Related News 
Leopard Graphics Update 1.0: Repeatable freezes, uninstalling... Leopard Graphics Update 1.0: Repeatable freezes, uninstalling...
 MacFixIt 02/18/08 11 PM 
Apple TV 2.0: More fixes for problems updating Apple TV 2.0: More fixes for problems updating
 MacFixIt 02/16/08 12 AM 
Bugs & Fixes: Assorted application crashes Bugs & Fixes: Assorted application crashes
 Mac 911 02/15/08 06 PM 
Microsoft fixes mass-delete bug in Office Microsoft fixes mass-delete bug in Office
 Macworld UK 02/15/08 11 AM 
Rush Limbaugh Begs Steve Jobs For Bug Fixes Rush Limbaugh Begs Steve Jobs For Bug Fixes
 Slashdot/Apple 02/15/08 09 AM 
Skype update adds 38 bug fixes, Leopard compatibility Skype update adds 38 bug fixes, Leopard compatibility
 MacNN 02/14/08 11 PM 
Bento 1.0v2 adds world languages, bug fixes, more Bento 1.0v2 adds world languages, bug fixes, more
 MacNN 02/14/08 06 AM 
10.5.2 fixes some problems, creates others? 10.5.2 fixes some problems, creates others?
 MacNN 02/14/08 02 AM 
Office 2004 11.4 fixes security bug Office 2004 11.4 fixes security bug
 MacNN 02/13/08 08 PM 
Apple TV software update Apple TV software update "Take2" now available; bugs and fixes
 MacFixIt 02/12/08 09 PM 
iLife Support 8.2 Includes iLife '08, Aperture 2 Fixes iLife Support 8.2 Includes iLife '08, Aperture 2 Fixes
 TheMacObserver 02/12/08 06 PM 
News: iPod classic Firmware 1.1.1 fixes hissing problem News: iPod classic Firmware 1.1.1 fixes hissing problem
 iPod Lounge 02/12/08 05 PM 
WebObjects 5.4.1 Bundles Bug Fixes WebObjects 5.4.1 Bundles Bug Fixes
 TheMacObserver 02/12/08 04 PM 
Mac OS X 10.5.2 Update Brings Welcome Fixes Mac OS X 10.5.2 Update Brings Welcome Fixes
 Slashdot/Apple 02/12/08 04 AM 
Apple releases fixes for OS X security issues Apple releases fixes for OS X security issues
 Mac Central 02/12/08 02 AM 
PandoCalendar 7.0.6 offers new features, bug fixes PandoCalendar 7.0.6 offers new features, bug fixes
 MacNN 02/09/08 02 AM 
Bugs & Fixes: Two Leopard glitches Bugs & Fixes: Two Leopard glitches
 Mac 911 02/08/08 08 PM 
QuickTime 7.4.1 does not fix playback, downgrade still works QuickTime 7.4.1 does not fix playback, downgrade still works
 MacFixIt 02/08/08 06 PM 
Apple Releases QuickTime 7.4.1 for Leopard, Tiger, and Panther Apple Releases QuickTime 7.4.1 for Leopard, Tiger, and Panther
 AppleLinks 02/08/08 08 AM 
Firefox 2.0.0.12 released; security fixes Firefox 2.0.0.12 released; security fixes
 MacFixIt 02/08/08 06 AM 
Liquid Ledger 2.1.2 offers over a dozen fixes Liquid Ledger 2.1.2 offers over a dozen fixes
 MacNN 02/07/08 10 PM 

Search

Mac Zicos
Tue October 7, 02:26 PM
update   {key13}