Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Apple QuickTime ActiveX Component Buffer Overrun Vulnerability



At 7:27 AM -0400 9/20/02, Frank Lowney wrote:
MacFixIt and others are reporting a vulnerability in the QT ActiveX component for QT5 that is not present in the QT6 version so I'm planning on pushing my audience to upgrade rather than expect them to fiddle with the "kill bit."

So, my question is this:

The recommended object/embed tag scheme includes code that prompts the download of the ActiveX component if it is not present. But what if it is present but of the QT5 variety? What happens then?

Is there a way to modify this code so as to compel the download and install of the most recent QT ActiveX component?

Not yet, but there will be shortly. We need to change a few things on the server first, but once this has been done there will be a way to author an object tag to require the new version of the ActiveX control. At that point IE will offer to download and install the QuickTime 6 ActiveX control if the user has the old version or if they have none at all.

The QuickTime 6 control _does not_ require QuickTime 6, it will work with QuickTime 3 or higher, so an upgrade to QuickTime 6 will not be required to use the new control.

Eric Carlson
QuickTime Engineering
_______________________________________________
quicktime-talk mailing list | email@hidden
Help/Unsubscribe/Archives: http://www.lists.apple.com/mailman/listinfo/quicktime-talk
Do not post admin requests to the list. They will be ignored.

References: 
 >Apple QuickTime ActiveX Component Buffer Overrun Vulnerability (From: Frank Lowney <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.