SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Integrating IT >> Middleware - Utilities

Apple patches 10 QuickTime bugs

Apple patches 10 QuickTime bugs

By:  Gregg Keizer  On: 01 Jun 2009 For: Computerworld US(NA) Creator

Monday's update was Apple's second this year for QuickTime, which has been patched a total of 17 times in 2009

Apple on Monday patched 10 critical vulnerabilities in QuickTime, including one that was hinted at in a Mac hacking book three months ago.

Eight of the bugs patched by QuickTime 7.6.2 affect both the Mac and Windows versions, while two others affect only QuickTime for Windows XP and Vista. Apple described all 10 as allowing "arbitrary code execution," a phrase it uses to describe the most serious threats that if exploited, could result in a PC or Mac hijacking. Unlike vendors such as Microsoft and Oracle, Apple doesn't rank the bugs it fixes with a scoring or labeling system.

Monday's update was Apple's second this year for the player, which has been patched a total of 17 times in 2009; last year, Apple patched 30 QuickTime vulnerabilities.

"They're what one would expect for QuickTime, file format processing bugs," said Andrew Storms, director of security operations at nCircle Network Security, in an instant message.

Storms had it right: All 10 vulnerabilities involved a file format issue of one sort or another. Three of the bugs were in how QuickTime parses movie files, two were in its handling of PICT image files and others were traced to problems dealing with JP2 (JPEG 2000), MS ADPCM-encoded (Adaptive Differential Pulse Code Modulation) audio, PhotoShop and animation file formats.

Apple has patched dozens of file format flaws in QuickTime over the years. Last September, for instance, it dealt out patches for problems in parsing PICT images, QTVR (QuickTime Virtual Reality) files, QuickTime movies, H.264-encoded movies and Indeo-encoded video.

File format vulnerabilities, and lots of them, are to be expected with a program like QuickTime, said Pedram Amini, manager of security research at 3com's Austin, Texas-based TippingPoint. "QuickTime has a huge attack surface," said Amini, "because of all the file formats it supports."

Six of the vulnerabilities were reported or co-reported to Apple by TippingPoint's bug bounty program, the second time in the last three weeks that a cash-for-bugs scheme has contributed the majority of a vendor's flaws. Last month, TippingPoint's rival, VeriSign's iDefense, reported 10 of the 14 PowerPoint vulnerabilities patched by Microsoft.

The large number of bugs attributed to TippingPoint were a timing conicidence, said Amini. Although the company typically passes along vulnerability reports to vendors as soon as it's vetted the bugs, there are times it holds them, then presents a batch to the vendor. "If we have several submitted for the same application, we like to get a full view of all the vulnerabilities to make sure there aren't any that overlap," said Amini.


Sign up for our Newsletters
Tags: patches, iTunes












Print |  Views: 1031   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Gregg Keizer Gregg Keizer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Apple gets 'Air' time for ultra-skinny notebook
Apple gets 'Air' time for ultra-skinny notebookSteve Jobs opens a manilla envelope to reveal a product that fits an entire Mac into a portable PC that weighs three kilograms and is less than half an inch thick. A Canadian reseller reacts
Apple offers a bushel of software patches
Apple offers a bushel of software patchesThe Mac maker's fixes deal with 45 vulnerabilities that span from its latest operating system to an open source file-sharing code. Plus: What Safari browser users need to know
Apple TV - sleek design, simple streaming
Apple TV - sleek design, simple streamingDesigned to provide the missing link between the media files in your iTunes library and today's modern televisions (and their accompanying audio-visual components), the Apple TV nicely simplifies the occasionally daunting process of viewing computer-based content on a television
Why hack a Mac?
by joaquim p. menezes - remember charlie miller? 
Apple IS in the enterprise - if you know where to look
just once i’d like to see steve jobs unveil a hot new product at macworld and watch the audience boo.i actually did hear some boos at macworld once, but
Imagine an iPhone built for business
she’s been treated as a hopeless case, but i had some sympathy for car

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.