QuickTime Update Plugs More Holes

QuickTime Update Plugs More Holes

Written By
Brian Prince
Brian Prince
Jun 10, 2008
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Apple has released a new version of QuickTime to fix five security issues that could allow hackers to take control of a system via malicious movie or image files.

The QuickTime 7.5 update comes roughly two months after Apple released Version 7.45 to plug 11 security holes in the application. This time around, the update addresses a series of buffer overflows, URL-handling flaws and memory corruption issues affecting Mac OS X and Windows XP and Vista users.

Among the issues is QuickTime’s handling of PixData structures that when processing a PICT image can cause a heap buffer overflow and lead to arbitrary code execution or cause the application to close unexpectedly. The flaw affects Windows Vista and XP Service Pack 2 users only, the company stated in its advisory.

A second heap buffer overflow vulnerability can be caused by opening a malicious PICT image file. This flaw, which can also lead to unexpected application termination or allow attackers to execute code, affects users of several versions of Mac OS X as well as Windows Vista and XP SP2 users.

The update also addresses a stack buffer overflow vulnerability in QuickTime’s handling of Indeo video codec content, which Apple has addressed by not rendering it. The final two vulnerabilities are a memory corruption issue caused by the way QuickTime handles AAC-encoded media content and URL handling issues. Both flaws affected several versions of Mac OS X as well as Windows XP SP2 and Windows Vista.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.