Original URL: http://www.channelregister.co.uk/2007/10/04/windows_quicktime_update/
Windows users of QuickTime, Apple's popular media player software, need to apply an update following the discovery of a serious security bug.
The vulnerability allows hackers to inject malicious code onto vulnerable systems providing users are tricked into opening a maliciously-constructed QTL (QuickTime Link) file. These files could be hosted on websites and disguised as links to movie clips or smut.
Apple published an update on Wednesday for QuickTime 7.2 on Windows Vista and XP SP2 that fixes the flaw. Users of QuickTime for Mac OS X are immune to the bug.
In a security notice (http://docs.info.apple.com/article.html?artnum=306560), Apple explains the bug stems from flaws in the way Windows versions of QuickTime handle URLs in the qtnext field of QTL files. The fix involves improving the handling of these URLs. ®
Media player users beware: more vulns ahead (10 December 2007)
http://www.channelregister.co.uk/2007/12/10/3ivx_mp4_vuln/
Latest QuickTime Exploit targets both Macs and PCs (29 November 2007)
http://www.channelregister.co.uk/2007/11/29/new_quicktime_exploit/
QuickTime streaming media exploit targets unpatched bug (26 November 2007)
http://www.channelregister.co.uk/2007/11/26/quicktime_exploit/
Leopard security bug puts Mail users at risk (20 November 2007)
http://www.channelregister.co.uk/2007/11/20/leopard_reintroduces_security_vuln/
With one bound, Apple is free of 54 security bugs (15 November 2007)
http://www.channelregister.co.uk/2007/11/15/behemoth_apple_patch_batch/
QuickTime update fixes code-execution holes (6 November 2007)
http://www.channelregister.co.uk/2007/11/06/new_quicktime_update/
Doomwatchers sound Windows and IE vuln alarm (19 September 2007)
http://www.channelregister.co.uk/2007/09/19/new_vulnerability_reports/
Apple patches more than a dozen holes in OS X (25 May 2007)
http://www.channelregister.co.uk/2007/05/25/osx_security_update/
QuickTime, not Safari, to blame for MacBook vuln (25 April 2007)
http://www.channelregister.co.uk/2007/04/25/quicktime_vuln_fells_mac/
MySpace-hosted malware exploits QuickTime flaw (16 March 2007)
http://www.theregister.co.uk/2007/03/16/myspace_quicktime_exploit/
Apple QuickTime update lances multiple bugs (6 March 2007)
http://www.channelregister.co.uk/2007/03/06/apple_quicktime_update/
Apple apps not ready for Vista (9 February 2007)
http://www.reghardware.co.uk/2007/02/09/apple_unready_for_vista/
© Copyright 2008