Brief Hands On Report--Apple Released QuickTime 7.1.3 with Security Updates

Also needed for the iTunes Store's new features is QuickTime 7.1.3. It is available for download via Software Update or as a stand-alone file from this Apple Web page. According to the ReadMe file,

QuickTime 7.1.3 is an important release that delivers numerous bug fixes and addresses critical security issues. This update is recommended for all QuickTime 7 users and is required for playback of content purchased in the iTunes Store.

Here are the details of the security updates:

CVE-2006-4381, CVE-2006-4386--Viewing a maliciously-crafted H.264 movie may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of H.264 movies. Credit to Sowhat of Nevis Labs, Mike Price of McAfee AVERT Labs, and Piotr Bania of piotrbania.com for reporting these issues.

CVE-2006-4382--Viewing a maliciously-crafted QuickTime movie may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of QuickTime movies. Credit to Mike Price of McAfee AVERT Labs for reporting this issue.

CVE-2006-4384--Viewing a maliciously-crafted FLC movie may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of FLC movies. Credit to Ruben Santamarta of reversemode.com working with the iDefense VCP Program, and Mike Price of McAfee AVERT Labs for reporting this issue.

CVE-2006-4388--Viewing a maliciously-crafted FlashPix may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of FlashPix files. Credit to Mike Price of McAfee AVERT Labs for reporting this issue.

CVE-2006-4389--Viewing a maliciously-crafted FlashPix may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of FlashPix files. Credit to Mike Price of McAfee AVERT Labs for reporting this issue.

CVE-2006-4385--Viewing a maliciously-crafted SGI image may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of SGI image files. Credit to Mike Price of McAfee AVERT Labs for reporting this issue.

We downloaded and installed QuickTime 7.1.3 with no problems. [Bill Fox and Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive