Brief Hands-On Report--Apple released QuickTime 7.1.6, a Security Update
QuickTime 7.1.6 delivers numerous bug fixes, addresses a critical security issue with QuickTime for Java and includes support for:
- Final Cut Studio 2
- Timecode and closed captioning display in QuickTime PlayerThis update is recommended for all QuickTime 7 users.
Here are the details:
QuickTime (CVE-2007-2175)--An implementation issue exists in QuickTime for Java, which may allow reading or writing out of the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously-crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional bounds checking when creating QTPointerRef objects. Credit to Dino Dai Zovi working with TippingPoint and the Zero Day Initiative for reporting this issue.
We downloaded and installed QuickTime 7.1.6 on numerous Macs including: MacBook Pro C2D, iMac C2D, iMac CD, PowerMac G4 Cube and PowerBook G4. We encountered no problems with the download and installation nor with brief use of QuickTime to view movie trailers or streaming video.
This update fixes the problem with QuickTime demonstrated at the recent Mac hacking contest. [Bill Fox & Dana Baggett]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?