Madrid, November 1, 2004 - Apple (*) has released version 6.5.2 of its multimedia player QuickTime, which corrects two important vulnerabilities that could allow an attacker to run remote arbitrary code.
One of these security flaws could allow an attacker to insert arbitrary code using a BMP image. This code would be run when the image were processed by QuickTime, due to a buffer overflow in the module that decrypts this format.
The second vulnerability lies in an integer overflow that could be exploited using an HTML document. This problem occurs when the value of an integer variable overruns the value assigned to it, resulting in a buffer overflow.
The first of these vulnerabilities affects both QuickTime for Windows and for Mac OS X, whereas the second only occurs under Windows.
QuickTime 6.5.2 released by Apple can be downloaded from: http://www.apple.com/quicktime/download/
(*) The bulletin published by Apple is available at: http://docs.info.apple.com/article.html?artnum=61798
Oxygen3 24h-365d
by Panda Software
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel