APPLE-SA-2008-02-06 QuickTime 7.4.1
site_archiver@lists.apple.com Delivered-To: security-announce@lists.apple.com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2008-02-06 QuickTime 7.4.1 QuickTime 7.4.1 is now available and addresses the following issue: CVE-ID: CVE-2008-0234 Available for: Mac OS X v10.3.9, Mac OS X v10.4.9 or later, Mac OS X v10.5 or later, Windows Vista / XP SP2 Impact: Visiting a malicious website may lead to an unexpected application termination or arbitrary code execution Description: A heap buffer overflow exists in QuickTime's handling of HTTP responses when RTSP tunneling is enabled. By enticing a user to visit a maliciously crafted webpage, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking. QuickTime 7.4.1 may be obtained from the Software Update application, or from the Apple Downloads site: http://www.apple.com/support/downloads/ For Mac OS X v10.5 or later The download file is named: "QuickTime741_Leopard.dmg" Its SHA-1 digest is: cf4af6969ff21ad03fdcb4289db62a61a00700a3 For Mac OS X v10.4.9 through Mac OS X v10.4.11 The download file is named: "QuickTime741_Tiger.dmg" Its SHA-1 digest is: 006ec419ad88a1d6c4a4695bad3eb9250abdc21d For Mac OS X v10.3.9 The download file is named: "QuickTime741_Panther.dmg" Its SHA-1 digest is: 4dfb9775dc84feaa49c096ccdc45109f8d6996c5 For Windows Vista / XP SP2 The download file is named: "QuickTimeInstaller.exe" Its SHA-1 digest is: 4bfe254cd7569ccad99ca6419e04ea8530e68a7f QuickTime with iTunes for Windows Vista / XP SP2 The download file is named: "iTunesSetup.exe" Its SHA-1 digest is: 9c1c0cdc2a1375af71f6423277a41cc2ce6273d1 QuickTime with iTunes (64 bit) for Windows Vista The download file is named: "iTunes64Setup.exe" Its SHA-1 digest is: 65f4c439b72de7ef7c53750866a04c247724be0f Information will also be posted to the Apple Product Security web site: http://docs.info.apple.com/article.html?artnum=61798 This message is signed with Apple's Product Security PGP key, and details are available at: http://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: 9.7.0.1012 wsBVAwUBR6opp8gAoqu4Rp5tAQhnTwf/ZztPe8eY4ToRT7DNpBdFSfmUFj0dIi6k XlgHyL9tRXP4JGNBifWw27EP/PcmvjiPgrSxwH/5AaRamVxTJkBCJT2wmmdfgr6v uxp/1C97V60H+ntCBZuxyWuIOLYTPotjh0szffRSPAkUWZAqX7u+H25AhOewBIZq LFEUcgNNeuRE6NLjtcD72HZG0RLH9Ag16ypAOfkG0YqiDoIiDfeo+Hue6ev1CQhI nAqDuRc84qKXZBuWwnFUeJCIVRk3w5snnUeTr1/xw7qPoat2LFC+mB4xp5DHbpTL GC4WVnCdBJ5aqdeH2hKTtG+cjWynwl+VX15diYlrt6pq+MFfgiu3UA== =hvlA -----END PGP SIGNATURE----- _______________________________________________ Do not post admin requests to the list. They will be ignored. Security-announce mailing list (Security-announce@lists.apple.com) Help/Unsubscribe/Update your Subscription: http://lists.apple.com/mailman/options/security-announce/site_archiver%40lis... This email sent to site_archiver@lists.apple.com
participants (1)
-
Apple Product Security