Apple patches QuickTime for 10 security holes

Apple on Monday released an updated version of its popular QuickTime software.

Version 7.6.2 closes 10 vulnerabilities, all of which could have been exploited to execute arbitrary code, according to an advisory. Attackers would have spread their exploits by persuading users into opening maliciously crafted movie files or images.

In January, Apple pushed out fixes for seven QuickTime bugs. Experts have said attackers prefer taking advantage of these type of client-side problems because many users trust popular multimedia software.

Apple on Monday also delivered the latest update to iTunes, according to a second advisory. Version 8.2 patches for one vulnerability, a stack buffer overflow issue that could be exploited if a user visits a malicious website.

This was the second iTunes update of the year.




More in News

Attackers use Skype, other IM apps to spread Liftoh trojan

Countries in Latin America have been the primary targets in this campaign, researchers say.

Scammers on the hunt for Memorial Day deal watchers

Like they do with major news events and other holidays, online fraudsters are seeking to cash in on the upcoming Memorial Day weekend.

Proxy research firm settles charges with SEC over client breach

Institutional Shareholder Services (ISS), a research firm the advises clients on voting in proxy fights, must pay $300,000 to the U.S. Securities and Exchange Commission.