Brief Hands-On Report--Apple released QuickTime 7.4.1

QuickTime 7.4.1 for Leopard, Tiger, Panther and Windows is available for download via Software Update and as a stand-alone file from this Apple Web page. According to Apple,

QuickTime 7.4.1 addresses security issues and improvescompatibility with third-party applications.

The details on the security issue are:

CVE-2008-0234--A heap buffer overflow exists in QuickTime's handling of HTTP responses when RTSP tunneling is enabled. By enticing a user to visit a maliciously crafted web page, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

I downloaded the update via Software Update and installed it with no difficulties in a MacBook Pro C2D running Mac OS X 10.5.1. In brief use of the updated Quicktime, included viewing embedded movie TV spots and Apple ads and movie trailers that launch the standalone QuickTime player, I experienced no problems. [Bill Fox]

Saw something? Send a tip or a correction

The archive ran on reader tips. What did you see, where, and do you want the credit? Something wrong on this page? Say so and it gets fixed.

Read by the editor. You get a copy by email. Never published without your say.

More in Reviews · This month in the archive