Brief Hands-On Report--Apple released QuickTime 7.4.1

QuickTime 7.4.1 for Leopard, Tiger, Panther and Windows is available for download via Software Update and as a stand-alone file from this Apple Web page. According to Apple,

QuickTime 7.4.1 addresses security issues and improvescompatibility with third-party applications.

The details on the security issue are:

CVE-2008-0234--A heap buffer overflow exists in QuickTime's handling of HTTP responses when RTSP tunneling is enabled. By enticing a user to visit a maliciously crafted web page, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

I downloaded the update via Software Update and installed it with no difficulties in a MacBook Pro C2D running Mac OS X 10.5.1. In brief use of the updated Quicktime, included viewing embedded movie TV spots and Apple ads and movie trailers that launch the standalone QuickTime player, I experienced no problems. [Bill Fox]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Reviews · This month in the archive