|
|
|

Apple Patches QuickTime, Updates iTunes
By: Nathan Eddy
2009-06-02
Article Rating:    / 2
There are 0 user comments on this Midmarket story.
Apple releases software updates for media players QuickTime and iTunes. Eight of the patches concern Apple and Microsoft operating systems, and two patches address vulnerabilities found only in Microsoft Vista and XP versions.Apple has issued a slew of critical patches for its QuickTime media player
and updated the digital media application iTunes. Version
7.6.2 of QuickTime received the majority of patches, targeted at patching
holes that allow maliciously crafted files to perform unexpected application
terminations or arbitrary code executions.
The iTunes upgraded software now supports iPhone and iPod touch with the iPhones
3.0 software update, and Version 8.2 also includes many accessibility
improvements and bug fixes, according to Apple. In March, Apple announced that
iPhone firmware Version 3.0 was due to be released in mid-2009.
One QuickTime patch fixes a memory corruption issue that existed in the
players handling of Sorenson 3 video files, while another addressed the issue
of a heap buffer overflow existing in the handling of FLC compression files.
Eight of the patches concern Apple and Microsoft operating systems, and two
patches address vulnerabilities found only in Microsoft Vista and XP versions.
The update is the second this year for QuickTime; the first, issued in January,
fixes seven security vulnerabilities. Microsoft noted in a security report
published in 2008 that, in the first half of 2008, a QuickTime flaw had been
the third-most attacked vulnerability for Windows XP users and the fourth-most
attacked for Vista customers.
Michael Oh, founder of the Apple-specific, Boston-based company Tech Superpowers,
said based on the support page for the QuickTime update, all of the
vulnerabilities related to the idea that it is theoretically possible for a
user to click on a URL, encoded in a certain way, and it may crash QuickTime or
be used to execute a code.
I wouldnt say its a large threat for the average user, but its a common
attack vector used by a lot of hackers sending out spam, so its a pretty
common type of thing you see out there, he said. He pointed out there are
theoretical hacks that can happen on any number of platforms, and singled out
Apples diligence in security issues.
Apple has a pretty serious stance on security and addressing these issues, he
said. They are very good at pushing these updates down to usersApple simply
sees those vulnerabilities, addresses them behind the scenes and then releases
the updates."
Oh said the stuff that really gets mainstream media attention, such as viruses
or Trojans, tends to be things that have a mechanism to propagate wildlyas the
term "virus" suggests. Its important to mention that none of the
vulnerabilities have any sort of mechanism to propagate like that, he said.
Thats a really critical thing you should look at with a security patch.
|
|
x}r㶲s\@♵M=Ҕlc-/K3NRJEĘ"H'g~u~|.{-`n4w~ IMל۔O]sSãw$5]2I=*rdz&9%GjL7 R}f]S k kL|Nშ:':@.Pk< Z535ԗoˏ~e0-ڎIQ6)Nմ<ش$)qHٗ#ѺC(D}!k[ tVN T| pTƖþ=az5EhDԸ#|x\'gώɀYgF
{.Qu^?C2]hj:TN`UƞfnڭaㅰA=c9p=^-
G&lwsDƞ4HCd"LJ^`:tm3G^C]õ]\./RF͌eCwtSz3]gԏPL0H6=~0[ QK8jk0~b[>4I:]Uh?BWuomzV[ucϝ;!{I̖%X䄍ER'>6O(|@I
uBģzr(˺79hmyaijTӪrT5X;rދWcm9/Ne,oF}RV5MQjUu7ںsm)kCq9}r>?'7;A:W@o&1W`J LTRBhd"Pc@GY:5=(G~W-b)ڑVP]GF[<,"J1~̢J
>'sK߾ڤ>9;O}1fP+M~(#3hؕgxg_:nN[7O7VGNפ9i~q!5M0\ܱ:֪V1?xej; dPp9LwjT{dZݓ/Wm2 ୫Odp"˭~|ֿ8' =--%wܿ ,_ fkķLJo$SNE ;-uͪZ*F`K7SI_s뮞;nZK}0[=RF&\ Д aC|`Mab&DJH7є6)`I˪
TI%嗋mQu3
.)J!"xN3E!\J!=!
g|8Jn.b?
[˚&feٜ҅%]WaLoQ#L
.uƍv"e.ڽ^C8^%g5F8,heݴ%!8WG5MGRŦc~+%YE*GX@8ʍ??1m!SGñA
3M:vٗ`: 0hvz?>RӚOCqOCGs>H2胎6ml8-ƙ"
,70}HOQI4Qp{4ڭm=K!pI}xXS9&ztmP`5$ǎC-ߟLs#08wɝ5y0f+wCPbLTM}PCn@}S(r`@}`sDoweC97(_fx?ɜ+)
%@FH@t"AђF*4 gscX"K"'A7;.VKŤ\*y"Jm':ݱ;PK/"ڹLX*QY,p[/ ͙JRd0U Q="`&Qea*0pRx5Vn/Zb٦By^i$w&]YJh5`HLMqsr`!gs3p#Eq"O(12,Xh4l:Z7ESsĽ'0Ќ7_azaAzs&2ٚM>BB13
=wʠ:'_
.g;N=\҇1 4fgܗd50J7n2gNP/h|WY 3EDVhdF!!
= \PȭT)w^IY䞅T_9YXX`~w,Rd0q6I
SXh8G/C4jM;24$֒f{ց$lJҰ.Z* ![r5}a6F]RZRKHDlPc/X+ezdч(e6LF%jIo2@n=ȢmD
jrA5 )Kۊ7q~4EiZ\-}sf8, J;
H璉IJ*6*SXSĝyд\"қy}@n&zg@>:`3 ǟGRlC2DhQ+}ne@ͤԪ)X[3T2.Q\&V,'`#z3FK~,Y\Xϗ+]65e&@0oʵLuzh<
VȲO[:٤ RTw~3KJAUc?$i?怚H|A2exL,`_#lʠ::7HҜ!ȅ@:*ZCc"Dk_(+`k受Aܧ^Ǭv"5w.Bāh<.Z6[Ro==>ئ\Q݂+6E)'>5 cd]Dz@4`D pHE&A|Zkhp\@U.(L19r2b*X[PTB$ᦼ6t߂ĒbtXQ =j={e|h322
yㅤZ
JLo39*GERgD+ϏxWG"MϨH_ଯ?p&7XfiY8E
~ }v݁/]r?0;|b2,` |/"ybėaE*㕴~>V6ʼnG =q?@*:2
XZ 0 (E{0qDLҀJ
5^ƙd)baJ)?oZyඨ,3YZH]bRYEGʚQ zCԃ3~Sb_@URTʞwZu^ߜ]hDA`!
Нv;#ؐCKAk1ʯ!q>:(TX7gmE{H^ac7U[@oF)-ғe4
O"|>675/Jp]8ýo~Qby2UG3Ⱦ N-(R!7;Jr zĀy@?uUJ _0LdT~#\yRfl|g]a+o22˓OFZ+UX37(p[c?֍Lnl*r12~
z:i0-aZ`O- vuhՂrO'(3߅rf>k5VΚ>9lv''<
hrõm7>Dv? sc{~O
n:R.R
r=ct3e}{c:7O7p/UU^S<:h93$P@hOXM\ k78$"ML
laƭbR/\f ?+:Tf#DU5}5O?>nVɵGڽv?fIG{EY(..n$UHU(V
$yUrmn,:
/6" ޜbl[
ezפ\+ԕKOe3q18@X=x}d6
5C+jBgyr
`3O?[IdYyVum4uH"5J7eVV5XI0iUI+TZ}2aU}/*\&IvSf
Ϛ8`rOn{W90J$7rQӊ5JR}'0Lp( rZ: GYdQ. |eR)*`7%ɠ K= j ;!O}+tSZ1wOXO\dK!OWƒ"'!Z+53,qvë
eVqm^?3Z cS7W_(1@ EE@jߵ?%
?/Ѝ ?PX1"NJE])w7V4M}ڽK͋/x:ȄyuO_u{~{y[;QAZ}RYԹl>$#.[RO50osV=(; J@ c䆷G$bw}\ɾ3zV^5[隿ð
Oa 區wsѼй_>w!#rlK^+ G y!KBV<'ux6q)q ڎ7M
,#LkC2Ȱ J_ƥ{j_sf녨kZ^Ok5WE.'27Le8ZFp[_aY ,d"0!Wtzc}E9 ,׀zB*ΛD:Ky9P^S(+RJ)"4FYO |FZu3_f3Rt4zQr:Ho1Mr!}K_cOߗfo4~ P=8Y,rh%縵vRt0?x>/mN9˝~DҼ"gÍ76w jE5p!XISB9kթ-ݱi'> fax!wl0q%՝b"0BٺCO,jm-̑sS)i# m$jRSfj# $_2HI,v+ht$lAzW jÚ]e.\|عm|d`L`ql)Za"|)Nr
9i`e>%;yRbQגZ4ҫoeW!9
|@s`=CD!aFCrWkb~=ZU${ݝ:hcɅp
`/awʜW#aZ ?Y./vg>&k?7nLq;f='Fs)= cm:{@'sF[ٿuoue's
C7+۽t9nia[nǡ8
0^t,4P$yUZ¶/WU$]d%FpZx>2&n_%3՛wD/
ZR{+!bi4V;Tf{s̷kD:>dO#@/mvc鼳 2>
AYCؖrbLp $`G-ݺܭ)g$`GDA|g˩g涣A jm3 Z0\9f>V2ÿ/&[qVL>>b |