Apple pushes out updates for QuickTime, iTunes

Apple on Tuesday issued a new version of QuickTime and iTunes to correct 11 vulnerabilities.

Nine of the flaws are present in QuickTime and are deemed "highly critical" by vulnerability tracking firm Secunia.

Most of the bugs are buffer overflow or memory corruption issues -- and they can be exploited when a user is tricked into watching a malicious movie file, which leads to a system crash or arbitrary code execution, according to an Apple advisory. Four of the nine QuickTime holes impact Windows Vista and XP machines, while the others affect Mac OS X platforms.

On the iTunes side, one of the bugs relates to a misleading warning screen that says unblocking iTunes Music Sharing doesn't affect firewall security when it actually does, according to another advisory. The other flaw is an integer overflow issue whereby a local user could gain unauthorized system privileges.

Apple advises users to upgrade to QuickTime 7.5.5 and iTunes 8.0.

Sign up to our newsletters

More in News

Bitcoin mining botnet has become one of the most prevalent cyber threats

Fortinet researchers have tracked 100,000 new ZeroAccess trojan infections per week, making the botnet very lucrative to its owners.

House Intelligence Committee OKs amended version of controversial CISPA

House Intelligence Committee OKs amended version of controversial ...

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

Judge rules hospital can ask ISP for help ...

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.