Apple patches Windows QuickTime bug
Look before you link
Posted in Enterprise Security, 4th October 2007 11:05 GMT
Free whitepaper – Vulnerability management buyer's checklist
Windows users of QuickTime, Apple's popular media player software, need to apply an update following the discovery of a serious security bug.
The vulnerability allows hackers to inject malicious code onto vulnerable systems providing users are tricked into opening a maliciously-constructed QTL (QuickTime Link) file. These files could be hosted on websites and disguised as links to movie clips or smut.
Apple published an update on Wednesday for QuickTime 7.2 on Windows Vista and XP SP2 that fixes the flaw. Users of QuickTime for Mac OS X are immune to the bug.
In a security notice, Apple explains the bug stems from flaws in the way Windows versions of QuickTime handle URLs in the qtnext field of QTL files. The fix involves improving the handling of these URLs. ®
Free whitepaper – Vulnerability management buyer's checklist

Analyst Keynote: The Register Agile Data Center Summit
Analyst Keynote: The Register Agile Data Center Summit
Enabling the Agile Data Center
Breaching Fort Apache.org - What went wrong?
Snow Leopard security - The good, the bad and the missing
US Dems fill inboxes with 419 scams
BlockMaster SafeStick hardware-encrypted USB drive