将文章归档于
Mac OS X
由. Ghost on 2007-06-01

昨天苹果又公布了一个 QuickTime 7.1.6 的重要安全更新,版本平台涉及 Mac OS X、Windows XP 以及 Windows 2000。两个重要漏洞都和 QuickTime for Java 有关:
QuickTime - CVE-ID: CVE-2007-2388
Available for: QuickTime 7.1.6 for Mac OS X and Windows
Impact: Visiting a malicious website may lead to arbitrary code execution
Description: An implementation issue exists in QuickTime for Java, which may allow instantiation or manipulation of objects outside the bounds of the allocated heap. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of Java applets. Credit to John McDonald, Paul Griswold, and Tom Cross of IBM Internet Security Systems X-Force, and Dyon Balding of Secunia Research for reporting this issue.
QuickTime - CVE-ID: CVE-2007-2389
Available for: QuickTime 7.1.6 for Mac OS X and Windows
Impact: Visiting a malicious website may lead to the disclosure of sensitive information
Description: A design issue exists in QuickTime for Java, which may allow a web browser's memory to be read by a Java applet. By enticing a user to visit a web page containing a maliciously crafted Java applet, an attacker can trigger the issue which may lead to the disclosure of sensitive information. This update addresses the issue by clearing memory before allowing it to be used by untrusted Java applets.
Mac OS X 用户通过通常的软件更新即可,建议及时升级。
Permalink: QuickTime 7.1.6 的重要安全更新
Trackback: http://publish.creative-weblogging.com/publish/mt-tb.pl/72853
Mr Wong
Vote for QuickTime 7.1.6 的重要安全更新:
|
分值情况: 7.40 / 5 评分
|
订阅
使用我们的搜索寻找其他有趣的文章
| CW工具栏 | ![]() |
| RSS | |
|
| |
| Yodao |
|
| Netvibes |
|
| Anothr | |
| 时事通讯 | |
| Follow us on Twitter! |






















