Brief Hands-On Report--Apple released QuickTime 7.1.5
QuickTime 7.1.5 delivers numerous bug fixes and addresses critical security issues. This update is recommended for all QuickTime 7 users.
There are seven security fixes involving the Mac OS X and Widows versions of QuickTime and one involving only the Windows version. Here are the Mac details:
CVE-2007-0712--Viewing a maliciously-crafted MIDI file may lead to an application crash or arbitrary code execution.
Description: A heap buffer overflow exists in QuickTime'shandling of MIDI files. By enticing a user to open a malicious MIDI file, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of MIDI files. Credit to Mike Price of McAfee AVERT Labs for reporting this issue.CVE-2007-0713--Viewing a maliciously-crafted Quicktime movie file may lead to an application crash or arbitrary code execution.
Description: A heap buffer overflow exists in QuickTime's handling of QuickTime movie files. By enticing a user to access a maliciously-crafted movie, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of QuickTime movies. Credit to Mike Price of McAfee AVERT Labs, Piotr Bania, and Artur Ogloza (Czestochowa, Poland) for reporting this issue.CVE-2007-0714--Viewing a maliciously-crafted Quicktime movie file may lead to an application crash or arbitrary code execution.
Description: An integer overflow exists in QuickTime's handlingof UDTA atoms in movie files. By enticing a user to access a maliciously-crafted movie, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of QuickTime movies. Credit to Sowhat of Nevis Labs, and an anonymous researcher working with TippingPoint and the Zero Day Initiative for reporting this issue.CVE-2007-0715--Viewing a maliciously-crafted PICT file may lead to an application crash or arbitrary code execution.
Description: A heap buffer overflow exists in QuickTime's handling of PICT files. By enticing a user to open a malicious PICT image file an attacker can trigger the overflow, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of PICT files. Credit to Mike Price of McAfee AVERT Labs for reporting this issue.CVE-2007-0716--Opening a maliciously-crafted QTIF file may lead to an
application crash or arbitrary code execution.
Description: A stack buffer overflow exists in QuickTime's handling of QTIF files. By enticing a user to access a maliciously-crafted QTIF file, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of QTIF files. Credit to Mike Price of McAfee AVERT Labs for reporting this issue.CVE-2007-0717--Opening a maliciously-crafted QTIF file may lead to an
application crash or arbitrary code execution
Description: An integer overflow exists in QuickTime's handling of QTIF files. By enticing a user to access a maliciously-crafted QTIF file, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of QTIF files. Credit to Mike Price of McAfee AVERT Labs for reporting this issue.CVE-2007-0718--Opening a maliciously-crafted QTIF file may lead to an application crash or arbitrary code execution
Description: A heap buffer overflow exists in QuickTime's handling of QTIF files. By enticing a user to access a maliciously-crafted QTIF file, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. This update addresses the issue by performing additional validation of QTIF files. Credit to Ruben Santamarta working with the iDefense Vulnerability Contributor Program, and JJ Reyes for reporting this issue.
We downloaded QuickTime 7.1.5 via Software Update and installed it on numerous Macs including: iMac Core Duo, iMac Core 2 Duo, Mac mini Core Duo, Power Mac G4 Cube and PowerBook G4 with no problems. We ran movie trailers on all Macs and did not encounter any issues. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?