Original URL: http://www.reghardware.co.uk/2007/05/30/latest_quicktime_security_patch/
Apple has plugged two holes in its QuickTime media player that could create serious security problems for people tricked into visiting malicious websites. The release, which is available for both Windows and Mac platforms, is Apple's second security patch in less than a week.
The most serious of the two vulnerabilities involves QuickTime's implementation of Java, which could allow for the manipulation of objects outside what should be allowed by the allocated heap.
"By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution," Apple said in this (http://docs.info.apple.com/article.html?artnum=305531) advisory.
Apple gave credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force and Dyon Balding of Secunia Research for reporting the flaw.
The other vulnerability also resides in the way QuickTime works with Java and could allow a maliciously crafted applet to read a web browser's memory. That could allow an attacker access to potentially sensitive information, Apple said.
If it seems like Apple security team has been working overtime, it's because it has. On Thursday, the maker of the increasingly popular iMac and iBook released (http://www.theregister.com/2007/05/25/osx_security_update/) its fifth mega patch in as many months. This fixed more than a dozen security vulnerabilities in OS X. Less than three weeks earlier, Apple patched another hole in QuickTime that could also allow a booby-trapped website to execute malicious code on unwitting Mac users.
QuickTime has emerged as one of the more vulnerable Apple packages, with at least four security updates this year. QuickTime's susceptibility is due in part to its ability to run on both Windows and OS X and its wide use (and occasional abuse (http://www.theregister.com/2007/03/16/myspace_quicktime_exploit/)) on sites such MySpace.
Apple's update is here (http://www.apple.com/support/downloads/). ®
Java 6 for OS X 'weeks away' (28 November 2007)
http://www.theregister.co.uk/2007/11/28/java_six_os_x/
QuickTime streaming media exploit targets unpatched bug (26 November 2007)
http://www.reghardware.co.uk/2007/11/26/quicktime_exploit/
QuickTime update fixes code-execution holes (6 November 2007)
http://www.theregister.co.uk/2007/11/06/new_quicktime_update/
Security maven: QuickTime flaw threatens PCs, Macs (12 September 2007)
http://www.theregister.co.uk/2007/09/12/quicktime_vulnerability_attacks_firefox/
Apple unwraps trio of aluminium iMacs (8 August 2007)
http://www.reghardware.co.uk/2007/08/08/apple_imac/
Serious security hole plugged in RealPlayer and HelixPlayer (28 June 2007)
http://www.theregister.co.uk/2007/06/28/realplayer_security_hole_plugged/
Apple releases Mac OS X 10.4.10 (21 June 2007)
http://www.reghardware.co.uk/2007/06/21/apple_updates_osx/
Apple TV gets its first critical security patch (20 June 2007)
http://www.reghardware.co.uk/2007/06/20/critical_appletv_patch/
Apple patches more than a dozen holes in OS X (25 May 2007)
http://www.reghardware.co.uk/2007/05/25/osx_security_update/
Apple patches security hole in QuickTime (2 May 2007)
http://www.reghardware.co.uk/2007/05/02/apple_quicktime_patch/
MySpace to be co-opted into Month of Bugs (20 March 2007)
http://www.theregister.co.uk/2007/03/20/myspace_momby/
MySpace-hosted malware exploits QuickTime flaw (16 March 2007)
http://www.theregister.co.uk/2007/03/16/myspace_quicktime_exploit/
Month of Apple Bugs scheme yields first fixes (5 January 2007)
http://www.reghardware.co.uk/2007/01/05/apple_fixes_project/
Unpatched bug bites QuickTime (3 January 2007)
http://www.theregister.co.uk/2007/01/03/quicktime_vuln/
Phishing worm hooks MySpace users (5 December 2006)
http://www.theregister.co.uk/2006/12/05/myspace_phishing_worm/
Security bugs take a bite out of Apple (7 December 2004)
http://www.theregister.co.uk/2004/12/07/apple_vuln/