Welcome | Log In
Security

Apple Plugs Gaping Hole in Media Player

Print Version
E-Mail Article
Reprints

Apple's new patch for its media player QuickTime prevents hackers from taking control of an unpatched computer from a remote location. Users caught without the security update could see trouble, according to Zippy Aima, research analyst with Frost & Sullivan. The patches apply to the Mac OS X and Windows versions of QuickTime.


Free WiFi Hotspot Locator from TechNewsWorld
Wondering where to find the nearest publicly available WiFi Internet access? Our global directory of more than 100,000 locations in 26 countries is a terrific tool for mobile computer users.

Apple (Nasdaq: AAPL) Latest News about Apple released patches for two flaws, one considered a serious hole, in its QuickTime Latest News about QuickTime media player -- just one week after releasing a bug catcher for the Mac OS X operating system.

The security Take the FREE Motorola AirDefense WLAN Security Assessment. Click here. fix to QuickTime 7.1.6 addresses two issues in the way QuickTime works on the Java platform.

The more serious problem could allow hackers to take control of an unpatched computer from a remote location. "By enticing a user to visit a Web page containing a maliciously crafted Java applet, an attacker can trigger the issue, which may lead to arbitrary code execution," Apple said in a security alert.

Other Problems

The second bug is considered to be less critical, yet somewhat dangerous, as it could allow an attacker to see sensitive information contained in the Web browser's memory. In that case, Java may allow malicious Web sites to trigger arbitrary code execution.

The update addresses the issue by performing additional validation of Java applets, the company said. The latest QuickTime update is available for both Mac OS and Windows users.

An unpatched flaw could cause plenty of problems for users unaware of the holes, according to Zippy Aima, a research analyst with Frost & Sullivan Latest News about Frost & Sullivan.

"Apple has always been pretty responsive to security threats, but users caught not paying attaching to the patches could find some trouble," Aima told MacNewsWorld.

Patching All Versions of QuickTime

The patches apply to the Mac OS X and Windows versions of QuickTime, and they can be downloaded from the company's site manually, according to Apple. Mac users can also retrieve them with the operating system's software update feature or use the optional Apple Software Update utility on Windows.

Earlier this month, security outfit Secunia Latest News about Secunia said one in three installed copies of QuickTime were not fully patched, making it three times more likely to pose a threat than Internet Explorer and six times more likely than Firefox.

In an alert of its own, Symantec (Nasdaq: SYMC) Latest News about Symantec pointed out that the new vulnerabilities were especially appealing to attackers because they affect both Macs and Windows-based PCs.

Keeping Guard

Apple's security team has been busy lately, as the company last week released Security Updates 2007-005 for its Mac OS X Tiger and Mac OS X Panther operating systems.

The Mac OS X patches fixed 17 flaws, several of which were considered to be critical.

Apple's automatic software updates for Windows and Mac OSes can deliver the updates to computers or can be downloaded manually.

Social Networking Toolbox:

Print Version E-Mail Article Reprints More by Tim Gray   RSS

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
Most E-Mailed Articles
ECT News Network Information
Locate Products and Services
Corporate
Reader Services
ECT News Network