Apple heeft een nieuwe versie van zijn mediaspeler QuickTime uitgebracht. QuickTime maakt deel uit van iTunes, maar wie geen behoefte heeft aan dat programma kan de mediaspeler ook los ophalen. QuickTime is voor Windows en Mac OS X beschikbaar en kan worden gebruikt om afbeeldingen te bekijken, muziek te beluisteren en filmbestanden af te spelen. Versie 7.7 lost een groot aantal beveiligingsproblemen op.
QuickTime 7.7
- CVE-2011-0245: Subreption LLC working with TippingPoint's Zero Day Initiative
Impact: Viewing a maliciously crafted pict file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0186: Will Dormann of the CERT/CC
Impact: Viewing a maliciously crafted JPEG2000 image with QuickTime may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0187: Nirankush Panchbhai and Microsoft Vulnerability Research (MSVR)
Impact: Visiting a maliciously crafted website may lead to the disclosure of video data from another site- CVE-2011-0209: Luigi Auriemma working with TippingPoint's Zero Day Initiative
Impact: Playing a maliciously crafted WAV file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0210: Honggang Ren of Fortinet's FortiGuard Labs
Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0211: Luigi Auriemma working with TippingPoint's Zero Day Initiative
Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0213: Luigi Auriemma working with iDefense VCP
Impact: Viewing a maliciously crafted JPEG file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0246: an anonymous contributor working with Beyond Security's SecuriTeam Secure Disclosure program
Impact: Viewing a maliciously crafted GIF image may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0247: Roi Mallo and Sherab Giovannini working with TippingPoint's Zero Day Initiative
Impact: Viewing a maliciously crafted H.264 movie file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0248: Chkr_d591 working with TippingPoint's Zero Day Initiative
Impact: Visiting a maliciously crafted website using Internet Explorer may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0249: Matt 'j00ru' Jurczyk working with TippingPoint's Zero Day Initiative
Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0250: Matt 'j00ru' Jurczyk working with TippingPoint's Zero Day Initiative
Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0251: Matt 'j00ru' Jurczyk working with TippingPoint's Zero Day Initiative
Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution- CVE-2011-0252: Matt 'j00ru' Jurczyk working with TippingPoint's Zero Day Initiative
Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution
