Apple heeft een nieuwe versie van zijn mediaspeler QuickTime uitgebracht. QuickTime maakt deel uit van iTunes, maar wie geen behoefte heeft aan dat programma kan de mediaspeler ook los ophalen. QuickTime is voor Windows en OS X beschikbaar, en kan worden gebruikt om afbeeldingen te bekijken, muziek te beluisteren en filmbestanden af te spelen. Versie 7.7.3 is alleen voor Windows uitgegeven en lost een groot aantal beveiligingsproblemen op.
About the security content of QuickTime 7.7.3
- A buffer overflow existed in the handling of REGION records in PICT files. This issue was addressed through improved bounds checking.
- A memory corruption issue existed in the handling of PICT files. This issue was addressed through improved bounds checking.
- A use after free issue existed in the QuickTime plugin's handling of '_qtactivex_' parameters within a HTML object element. This issue was addressed through improved memory handling.
- A buffer overflow existed in the handling of the transform attribute in text3GTrack elements. This issue was addressed through improved bounds checking.
- Multiple buffer overflows existed in the handling of style elements in QuickTime TeXML files. These issues were addressed through improved bounds checking.
- A buffer overflow existed in the QuickTime plugin's handling of MIME types. This issue was addressed through improved bounds checking.
- A use after free issue existed in the QuickTime ActiveX control's handling of the Clear() method. This issue was addressed through improved memory management.
- A buffer overflow existed in the handling of Targa image files. This issue was addressed through improved bounds checking.
- A buffer overflow existed in the handling of 'rnet' boxes in MP4 files. This issue was addressed through improved bounds checking.
