Brief Hands-On Report--QuickTime 7.0.1 Updater
QuickTime 7.0.1 provides several important bug fixes, a security enhancement, and improved compatibility with Final Cut Studio. This update is recommended for all QuickTime 7 users.
Here are the details on the security improvement for the Quartz Composer Plugin:
CVE-ID: CAN-2005-1334
Available for: QuickTime 7.0
Impact: With QuickTime 7.0, a QuickTime movie containing a
maliciously crafted Quartz Composer object can leak a data to an
arbitrary web location.Description: Quartz Composer objects can be wrapped in a QuickTime
track, and can be delivered as a QuickTime movie. With QuickTime
7.0, a Quartz Composer object can gather local data and send it via
an encoded URL to an arbitrary web location. The QuickTime 7.0.1
update modifies the QuickTime Quartz Composer Plugin to prevent
access to remote web locations. This issue does not occur in
QuickTime for Windows. Credit to David Remahl of www.remahl.se/david
for reporting this issue.
We downloaded and installed QuickTime 7.0.1 Update on numerous Macs running QuickTime 7 on 10.4.1 and 10.3.9 with no apparent problems. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?