Feeds

Apple plugs two QuickTime holes

Second security patch in less than a week

High performance access to file storage

Apple has plugged two holes in its QuickTime media player that could create serious security problems for people tricked into visiting malicious websites. The release, which is available for both Windows and Mac platforms, is Apple's second security patch in less than a week.

The most serious of the two vulnerabilities involves QuickTime's implementation of Java, which could allow for the manipulation of objects outside what should be allowed by the allocated heap.

"By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution," Apple said in this advisory.

Apple gave credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force and Dyon Balding of Secunia Research for reporting the flaw.

The other vulnerability also resides in the way QuickTime works with Java and could allow a maliciously crafted applet to read a web browser's memory. That could allow an attacker access to potentially sensitive information, Apple said.

If it seems like Apple security team has been working overtime, it's because it has. On Thursday, the maker of the increasingly popular iMac and iBook released its fifth mega patch in as many months. This fixed more than a dozen security vulnerabilities in OS X. Less than three weeks earlier, Apple patched another hole in QuickTime that could also allow a booby-trapped website to execute malicious code on unwitting Mac users.

QuickTime has emerged as one of the more vulnerable Apple packages, with at least four security updates this year. QuickTime's susceptibility is due in part to its ability to run on both Windows and OS X and its wide use (and occasional abuse) on sites such MySpace.

Apple's update is here. ®

High performance access to file storage

More from The Register

next story
Report: Apple seeking to raise iPhone 6 price by a HUNDRED BUCKS
'Well, that 5c experiment didn't go so well – let's try the other direction'
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Zucker punched: Google gobbles Facebook-wooed Titan Aerospace
Up, up and away in my beautiful balloon flying broadband-bot
Nvidia gamers hit trifecta with driver, optimizer, and mobile upgrades
Li'l Shield moves up to Android 4.4.2 KitKat, GameStream comes to notebooks
Gimme a high S5: Samsung Galaxy S5 puts substance over style
Biometrics and kid-friendly mode in back-to-basics blockbuster
AMD unveils Godzilla's graphics card – 'the world's fastest, period'
The Radeon R9 295X2: Water-cooled, 5,632 stream processors, 11.5TFLOPS
Sony battery recall as VAIO goes out with a bang, not a whimper
The perils of having Panasonic as a partner
NORKS' own smartmobe pegged as Chinese landfill Android
Fake kit in the hermit kingdom? That's just Kim Jong-un-believable!
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.