Hands-On Report--Apple QuickTime 7.3.1 Update Installation & Use

Apple released QuickTime 7.3.1 for Mac OS X 10.5.x, 10.4.9+ and 10.3.9. It is available via Software Update or from MacUpdate.com or this Apple Web page. According to the ReadMe file,

QuickTime 7.3.1 addresses security issues.

Here are the QuickTime 7.3.1 security details:

CVE-2007-6166--A buffer overflow exists in QuickTime's handling of Real Time Streaming Protocol (RTSP) headers. By enticing a user to view a maliciously crafted RTSP movie, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue by ensuring that the destination buffer is sized to contain the data.

CVE-2007-4706--A heap buffer overflow exists in QuickTime's handling of QTL files. By enticing a user to view a maliciously crafted QTL file, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

CVE-2007-4707--Multiple vulnerabilities exist in QuickTime's Flash media handler, the most serious of which may lead to arbitrary code execution. With this update, the Flash media handler in QuickTime is disabled except for a limited number of existing QuickTime movies that are known to be safe. Credit to Tom Ferris of Adobe Secure Software Engineering Team (ASSET), Mike Price of McAfee Avert Labs, and security researchers Lionel d'Hauenens & Brian Mariani of Syseclabs for reporting this issue.

We downloaded and installed QuickTime 7.3.1 via Software Update and installed it on a number of Macs including: 1.66GHz Mac mini Core Duo (10.5.1), aluminum 24" 2.8GHz iMac Core 2 Duo (10.5.1), white 24" 2.33GHz iMac Core 2 Duo (10.4.11), 15" 2.4GHz MacBook Pro Core 2 Duo (10.5.1), 1.4GHz PowerMac G4 Cube (10.5.1) and 1.4GHz 12" PowerBook G4 (10.5.1). We ran several movies and trailers on each Mac without encountering any problems. [Bill Fox & Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive