整个网络 苹果硬件 集会信息 iPhone Mac OS X Windows Live 奇趣杂景 微软动态

五月 31, 2007

QuickTime 7.1.6 的重要安全更新

由. Ghost 将文章归档于 Mac OS X

QuickTime 7.1.6 的重要安全更新

昨天苹果又公布了一个 QuickTime 7.1.6 的重要安全更新,版本平台涉及 Mac OS X、Windows XP 以及 Windows 2000。两个重要漏洞都和 QuickTime for Java 有关:

QuickTime - CVE-ID: CVE-2007-2388

Available for: QuickTime 7.1.6 for Mac OS X and Windows

Impact: Visiting a malicious website may lead to arbitrary code execution

Description: An implementation issue exists in QuickTime for Java, which may allow instantiation or manipulation of objects outside the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of Java applets. Credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force, and Dyon Balding of Secunia Research for reporting this issue.

QuickTime - CVE-ID: CVE-2007-2389

Available for: QuickTime 7.1.6 for Mac OS X and Windows

Impact: Visiting a malicious website may lead to the disclosure of sensitive information

Description: A design issue exists in QuickTime for Java, which may allow a web browser's memory to be read by a Java applet. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to the disclosure of sensitive information. This update addresses the issue by clearing memory before allowing it to be used by untrusted Java applets.


Mac OS X 用户通过通常的软件更新即可,建议及时升级。

广告


固定链接: QuickTime 7.1.6 的重要安全更新
关键词: OSX  安全更新  QuickTime  软件 

引用: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/72853



广告


广告


广告


CW工具栏安设
RSSrss   | 所有的部落格订阅选择
Googlegoogle  |   什么是RSS?
YodaoYodao
Netvibes Netvibes
AnothrAnothr
时事通讯
点击联系广告合作.

使用我们的搜索寻找其他有趣的文章

  • Extras

广告 -
这里订您的.


 
点击联系广告合作.


  • 推荐书

  • "关于 Mac 的 Blog,文章很有质量。"
    - from Livid