Hands-On Report--Security Update (QuickTime 7.1.6) 1.0 released by Apple

Apple released Security Update (QuickTime 7.1.6) 1.0. It is available via Software Update or as a stand-alone updater for download from this Apple Web page. According to Apple,

This update is recommended for all users and improves the security of QuickTime 7.1.6.

Here are the details:

QuickTime--CVE-2007-2388--An implementation issue exists in QuickTime for Java, which may allow instantiation or manipulation of objects outside the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of Java applets. Credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force, and Dyon Balding of Secunia Research for reporting this issue.

QuickTime--CVE-2007-2389--A design issue exists in QuickTime for Java, which may allow a web browser's memory to be read by a Java applet. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to the disclosure of sensitive information. This update addresses the issue by clearing memory before allowing it to be used by untrusted Java applets.

We downloaded and installed Security Update (QuickTime 7.1.6) 1.0 via Software Update on our MacBook Pro Core 2 Duo and iMac Core Duo with no problems. We tried a number of Web pages with QuickTime content and played several movie clips with no problems.

[Bill Fox & Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive