Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Quicktime has been updated to 7.3.1. fyi.

http://docs.info.apple.com/article.html?artnum=307176


About the security content of QuickTime 7.3.1
Last Modified on: December 13, 2007
Article: 307176
This document describes the security content of QuickTime 7.3.1, which can be downloaded and installed via Software Update preferences, or from Apple Downloads.

For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.

For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key."

Where possible, CVE IDs are used to reference the vulnerabilities for further information.

To learn about other Security Updates, see "Apple Security Updates."

QuickTime 7.3.1
QuickTime

CVE-ID: CVE-2007-6166

Available for: Mac OS X v10.3.9, Mac OS X v10.4.9 or later, Mac OS X v10.5 or later, Windows Vista, XP SP2

Impact: Viewing a maliciously crafted RTSP movie may lead to an unexpected application termination or arbitrary code execution

Description: A buffer overflow exists in QuickTime's handling of Real Time Streaming Protocol (RTSP) headers. By enticing a user to view a maliciously crafted RTSP movie, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue by ensuring that the destination buffer is sized to contain the data.

QuickTime

CVE-ID: CVE-2007-4706

Available for: Mac OS X v10.3.9, Mac OS X v10.4.9 or later, Mac OS X v10.5 or later, Windows Vista, XP SP2

Impact: Viewing a maliciously crafted QTL file may lead to an unexpected application termination or arbitrary code execution

Description: A heap buffer overflow exists in QuickTime's handling of QTL files. By enticing a user to view a maliciously crafted QTL file, an attacker may cause an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking.

QuickTime

CVE-ID: CVE-2007-4707

Available for: Mac OS X v10.3.9, Mac OS X v10.4.9 or later, Mac OS X v10.5 or later, Windows Vista, XP SP2

Impact: Multiple vulnerabilities in QuickTime's Flash media handler

Description: Multiple vulnerabilities exist in QuickTime's Flash media handler, the most serious of which may lead to arbitrary code execution. With this update, the Flash media handler in QuickTime is disabled except for a limited number of existing QuickTime movies that are known to be safe. Credit to Tom Ferris of Adobe Secure Software Engineering Team (ASSET), Mike Price of McAfee Avert Labs, and security researchers Lionel d'Hauenens & Brian Mariani of Syseclabs for reporting this issue.

Keywords: ktech kqt7 ksecurity
 
iPhone & BlockBuster Video

Well, I could not open a thread in the place I thought this belonged in, but here I go anyway. ;)

I was speaking with a manager at one of the local BlockBuster's here and they stated that BlockBuster was in communication with Apple to bring BlockBuster Movies to the iPhone via downlaod, similar to the movie download from iTunes. :rolleyes:

If this turns true, it will open a whole new market for iPhone movies! The manager indicated it was slated for the 1st or 2nd quarter of 2008! :apple:

Gunny :cool:
 
New Direction for iTunes?

Since the loss of NBC and its subsidiaries and the potential loss of Universal Music Group on iTunes (according to an article in the Jan Wired Magazine), I am hoping that Apple is able to rectify the agreements between these content providers, or perhaps take iTunes in a new direction.

One of the biggest features that I think we have been missing on iTunes has been digital software delivery. Several gaming companies offer this purchasing method of their software over the web - namely Electronic Arts - for the PC, but the Mac crowd has been left out in the cold without a service such as this. EA's web store is limited to gaming. It would be great to see Apple develop the premier web store for the digital delivery of all types of Mac software - and maybe later expand into the PC market ;). Besides, even if Apple chose to focus on gaming software, it would be a big push toward making the Mac a viable gaming platform. The nearest Apple Store is just too far away for some of us....
 
I was speaking with a manager at one of the local BlockBuster's here and they stated that BlockBuster was in communication with Apple to bring BlockBuster Movies to the iPhone via downlaod, similar to the movie download from iTunes. :rolleyes:

If this turns true, it will open a whole new market for iPhone movies! The manager indicated it was slated for the 1st or 2nd quarter of 2008! :apple:
That would perfectly match with a rumored launch of a "new" 3G version of the iPhone with more memory.
 
Well, I could not open a thread in the place I thought this belonged in, but here I go anyway. ;)

I was speaking with a manager at one of the local BlockBuster's here and they stated that BlockBuster was in communication with Apple to bring BlockBuster Movies to the iPhone via downlaod, similar to the movie download from iTunes. :rolleyes:

If this turns true, it will open a whole new market for iPhone movies! The manager indicated it was slated for the 1st or 2nd quarter of 2008! :apple:

Gunny :cool:

I worked for blockbuster, and let me tell you, the managers are not privy to any information of that kind...could it happen, sure...it would help Apple out in the selection on iTunes, however what would happen with Universal Movies...Apple is in dispute with them as it is.
 
Fixed the bitrate importing bug!!

Yeah!

Just imported two CD's at a Constant Bit Rate of 256. At last. The annoying bug (and all the nonsense written about it from those who should have known better) is gone! yeah!!!!!

At last my iPod can have some fresh food!

Marky
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.