• On CBS MoneyWatch: Report: DON'T Buy the iPhone 4
advertisement
January 15, 2008 11:15 AM PST

QuickTime 7.4 released: security holes plugged

by CNET staff

Alongside iTunes 7.6, Apple today released QuickTime 7.4. According to Software Update (currently the only method of obtaining the new release), this version includes:

  • Numerous bug fixes
  • Support for iTunes

The new release also includes the following security enhancements:

  • "Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution A memory corruption issue exists in QuickTime's handling of Sorenson 3 video files. This may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of Sorenson 3 video files. Credit to Joe Schottman of Virginia Tech for reporting this issue.
  • Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution A memory corruption issue exists in QuickTime's handling of Macintosh Resource records in movie files. Opening a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of movie files. Credit to Jun Mao of VeriSign iDefense Labs for reporting this issue.
  • Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution A memory corruption issue exists in QuickTime's parsing of Image Descriptor (IDSC) atoms. Opening a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of Image Descriptor atoms in movie files. Credit to Cody Pierce of TippingPoint DVLabs for reporting this issue.
  • Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution A buffer overflow may occur while processing a compressed PICT image. Opening a maliciously crafted compressed PICT file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by terminating decoding when the result would extend beyond the end of the destination buffer. Credit to Chris Ries of Carnegie Mellon University Computing Services for reporting this issue."

Feedback? Late-breakers@macfixit.com.

Resources

  • Late-breakers@macfixit.com
  • More from Late-Breakers
  • Recent posts from MacFixIt
    iTunes 10 user interface sees some minor changes
    Apple seeds iOS 4.1 Gold Master to developers
    Possible fix for Harman Kardon iSub problems with PowerPC Macs
    Precautions to take before installing iTunes 10
    A reminder on how to reset your Mac's system password
    Mail messages appearing blank
    Adobe Lightroom update brings direct Facebook publishing; Camera Raw 6.2 released
    Weekly troubleshooting utilities update
    Add a Comment (Log in or register) (6 Comments)
    • prev
    • next
    by SERBIAN--2008 January 15, 2008 12:37 PM PST
    Unfortenantly this update broke the ability to load MPEG2 video track together with .wav or .aif audio - e.g. when you click on .m2v /MPEG2 Video track/ and if you have the .wav audio with the same name in same folder as video, QT 7.4 wont open audio, only video...Which is a dissaster for many apps including mine - MPEG2 Works 4..Now I have to figure it out what a hell is goin on again..
    Reply to this comment
    by arkangel_3 January 15, 2008 9:09 PM PST
    So...here I am, as usual after a Quick Time update seeing if it plays and/or records (I have Quick Time Pro). Guess what? Plays fine, but it will not record. It says it is receiving no data from the camera and///or audio, when I clearly can say it is.

    Anyone else with this issue?
    Reply to this comment
    by dcoudert January 16, 2008 8:19 AM PST
    Using Leopard... updated quicktime.. (Have QT Pro) QT movies (even on Apple page) would not play in Safari. Deleted the Quicktime Plugin.plugin and everything works okay again. It would be really nice not to have to do this.
    Reply to this comment
    by svenhh1 January 16, 2008 10:07 AM PST
    After the update I am not able to play some .mp4-files (MPEG-4 / H.264). Tested with four Macs (10.4.11 or 10.5.1). QT 7.3 still plays the files.
    Reply to this comment
    by dcoudert January 16, 2008 10:07 AM PST
    <class="merchant"><span>&#62;</span><div class="datestamp"><i>This is a reply to a previous comment by svenhh1</i></div></class><br />
    Yep.... me too.. VLC plays them okay but not quicktime 7.4... Funny, though, it's not every .mp4 !
    Reply to this comment
    by Ron L January 16, 2008 10:38 AM PST
    If you take the following precautions I've found that QT and iT will work fine. And since they are such important apps I believe it is definitely worth the extra minutes this takes (As with major upgrades it's worth taking the extra time.)

    While running 10.5.1 I ran DFA and Repaired permissions first.

    Then I did a Safe Boot (which performs several maintenance functions as well as disabling numerous non-essential third party apps, etc.) and installed iTunes 7.6. Then I installed QuickTime 7.4.

    All is working fine. (I've done many tests.)

    IMHO if you do the above you should not have problems. It often appears those that don't follow safe installations are the ones that have glitches. Sure it takes maybe another ten minutes to do this, but it can save a lot of headaches.

    HTH
    Reply to this comment
    (6 Comments)
    • prev
    • next