Site icon MacTech.com

Apple fixes QuickTime flaw with Security Update

Apple today released Security Update 2007-001 via its Software Update Pane and on the Web. Apple says: “A buffer overflow exists in QuickTime’s handling of RTSP URLs. By enticing a user to access a maliciously-crafted RTSP URL, an attacker can trigger the buffer overflow, which may lead to arbitrary code execution. A QTL file that triggers this issue has been published on the Month of Apple Bugs web site (MOAB-01-01-2007). This update addresses the issue by performing additional validation of RTSP URLs.”

Exit mobile version