Brief Hands-On Report--Apple released Security Update 2007-001

Security Update 2007-001 is available for download via Software Update or as a stand-alone file from this Apple Web page. There are separate Intel-based and PowerPC-based updaters. According to Apple, the update fixes a QuickTime security issue. Here are the details:

QuickTime
CVE-ID: CVE-2007-0015
Available for: QuickTime 7.1.3 on Mac OS X v10.3.9, Mac OS X Server
v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8, Windows XP/2000
Impact: Visiting malicious websites may lead to arbitrary code
execution
Description: A buffer overflow exists in QuickTime's handling of RTSP
URLs. By enticing a user to access a maliciously-crafted RTSP URL, an
attacker can trigger the buffer overflow, which may lead to arbitrary
code execution. A QTL file that triggers this issue has been
published on the Month of Apple Bugs web site (MOAB-01-01-2007). This
update addresses the issue by performing additional validation of
RTSP URLs.

We downloaded Security Update 2007-001 and installed it on several Macs, including a MacBook Pro C2D and iMac Core Duo without a problem. We also used QuickTime to view various videos and QuickTime content on the Web with no problems. [Bill Fox & Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive