News
Articles
Blog
All Keywords
From
To
Search
Filter
View
Poll

Security Update 2007-001

by linathael . Original by MacEnsteph - 24/01/2007 10:56:54 CET
A security update is available for Panther and Tiger, and available either from Apple website or Software update panel.
This document describes Security Update 2007-001, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.
Security Update 2007-001
QuickTime
CVE-ID: CVE-2007-0015
Available for: QuickTime 7.1.3 on Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8, Windows XP/2000
Impact: Visiting malicious websites may lead to arbitrary code execution
Description: A buffer overflow exists in QuickTime's handling of RTSP URLs. By enticing a user to access a maliciously-crafted RTSP URL, an attacker can trigger the buffer overflow, which may lead to arbitrary code execution. A QTL file that triggers this issue has been published on the Month of Apple Bugs web site (MOAB-01-01-2007). This update addresses the issue by performing additional validation of RTSP URLs.
Additional information: http://docs.info.apple.com/article.html?artnum=61798-en

Printer Friendly
Tip a friend
List View
Daily View
Full View
Previous
Next
Delicious Digg Facebook Technorati Reddit Blogmarks ShareThis