
Serious QuickTime flaws put Macs and PCs at risk...
By Joris Evers
Published: 15 May 2006 08:50 BST
Serious flaws in Mac OS X and QuickTime software could put Macintosh and Windows systems at risk of cyber attack, Apple has warned.
In a pair of security alerts released on Thursday, Apple outlined 31 flaws that affect various versions of the operating system and a dozen vulnerabilities in its QuickTime media player software. Security experts have deemed the issues "critical" but Apple does not provide a severity rating. Fixes are available.
The Mac OS X vulnerabilities lie in various components of the operating system and affect both the server and client versions, Apple said in an advisory. An attack could be launched using some of the bugs by creating a malformed file, or by building a malicious website and enticing someone to visit it, the company said.
The French Security Incident Response Team, a security-monitoring company, said in an advisory: "These flaws could be exploited by attackers to execute arbitrary commands, bypass security restrictions, disclose sensitive information or cause a denial of service."
The patches indicate Apple is having a hard time completely resolving a security flaw that surfaced earlier this year. They fix an issue in the "download validation" function, a feature designed to protect Mac users from installing harmful code from a malicious website or email - a risk more familiar to Windows users.
Apple added the function in a security update released in early March. Two weeks later, it issued another update to fix some problems with the feature. Thursday's fix tackles another issue: the download validation may be bypassed if a file has a long name, Apple said.
Critics have argued the download validation function is not enough to address the installation risk, and that Apple needs to correct the problem at a lower level in the operating system.
The QuickTime flaws put both Mac OS X and Windows computers at risk of compromise. All of the vulnerabilities exist because of errors in the way the media player software handles certain files. Specially crafted files in certain media formats - including AVI, Flash, JPEG, MPEG4 and QuickTime - could allow an intruder to hijack a vulnerable system, Apple said in an advisory.
Apple's security update 2006-003 for Mac OS X and the QuickTime patch can be downloaded and installed via Software Update preferences or from the Apple Downloads website.
Joris Evers writes for CNET News.com
Ahem, so Mac software and OSes are entirely immune...
Julian Nicholls
I have now been a Mac owner for 3 years since conv...
Matt Brown
Walt Mossberg, one of the world's most respected t...
Dru Richman
Good to see Matt Brown perpetuating silly myths ab...
Norman J Cesar
You will be working in a cross platform environment and should therefore have proven experience working with both windows and mac OS X. My client: a ...
Business Interaction Production Support and Professional Services The candidate will be required to answer detailed questions regarding the ...
Your management and co-ordination will include that of break fix solutions, projects and the networks. Any exposure to the Mac OS 10 environment ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Ruth Hoy Legal Eye: Who's tracking your online trail? Putting privacy under the spotlight
Louella Fernandes Quocirca's Straight Talking: License this software Time to get your house in order