CERT mailing list archives

Current Activity - Apple Releases QuickTime 7.6.7


From: Current Activity <us-cert () us-cert gov>
Date: Fri, 13 Aug 2010 08:56:02 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

Apple Releases QuickTime 7.6.7

Original release date: August 13, 2010 at 8:08 am
Last revised: August 13, 2010 at 8:08 am


Apple has released QuickTime 7.6.7 for Windows to address a
vulnerability. This vulnerability is due to a stack buffer overflow
that exists in QuickTime error logging. By convincing a user to open a
specially crafted movie file, a remote attacker may be able to execute
arbitrary code or cause a denial-of-service condition.

US-CERT encourages users and administrators to review Apple article
HT4290 and update to QuickTime 7.6.7 to help mitigate the risks.

Relevant Url(s):
<http://support.apple.com/kb/HT4290>

====
This entry is available at
http://www.us-cert.gov/current/index.html#apple_releases_quicktime_7_61

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBTGVA0j6pPKYJORa3AQJAwggAjRRYo2J1dE/NZtUeSDaoUnbENfvEjqiT
E288ryRS9FrUHVvq3AVsjRJ1I9EqTZ+1wfBE+b6saYZUxuvTLHDpnuABNnv/h3wD
V4O74AOdLf7R+yXBHzrs5+ha6A4I3YSM2qWgUePPD+YoecgPInGCH/v9iDW9JtnV
2+ulgB7Au789Im2ctYHAEFUb22d6t9OnFfAA3kQDgK2Nmct8B5sliGo49ViO/YPI
Q02cV4K8dtgFt7DZy5Z89lQ+9VY9qSifeopdW+8PuUCbMN1Hsd6cGPlymY3kmu5S
BT9SQBXbdyVB0SlI2wtF2FGokz8PdZp1+tEgbFAsqojPyWyarB966Q==
=zfzt
-----END PGP SIGNATURE-----


Current thread: