五月 31, 2007
QuickTime 7.1.6 的重要安全更新
由. Ghost 将文章归档于 Mac OS X

昨天苹果又公布了一个 QuickTime 7.1.6 的重要安全更新,版本平台涉及 Mac OS X、Windows XP 以及 Windows 2000。两个重要漏洞都和 QuickTime for Java 有关:
QuickTime - CVE-ID: CVE-2007-2388
Available for: QuickTime 7.1.6 for Mac OS X and Windows
Impact: Visiting a malicious website may lead to arbitrary code execution
Description: An implementation issue exists in QuickTime for Java, which may allow instantiation or manipulation of objects outside the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of Java applets. Credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force, and Dyon Balding of Secunia Research for reporting this issue.
QuickTime - CVE-ID: CVE-2007-2389
Available for: QuickTime 7.1.6 for Mac OS X and Windows
Impact: Visiting a malicious website may lead to the disclosure of sensitive information
Description: A design issue exists in QuickTime for Java, which may allow a web browser's memory to be read by a Java applet. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to the disclosure of sensitive information. This update addresses the issue by clearing memory before allowing it to be used by untrusted Java applets.
Mac OS X 用户通过通常的软件更新即可,建议及时升级。
固定链接: QuickTime 7.1.6 的重要安全更新
关键词:
OSX 安全更新 QuickTime 软件
引用: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/72853







































